Remote Code Execution Vulnerability in Microsoft Windows Font Library
CVE-2015-6108

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 December 2015

Summary

A vulnerability exists in the Windows font library that enables remote attackers to execute arbitrary code by crafting malicious embedded fonts. This flaw affects a wide range of Microsoft products, including various versions of Windows and Office applications. Successful exploitation of this vulnerability could lead to a complete compromise of the affected system, allowing unauthorized access and control. Users are advised to apply security patches and updates provided by Microsoft to mitigate the risk.

References

EPSS Score

39% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.