Executive brief
A remote code execution vulnerability exists in the Microsoft Windows DirectWrite library when parsing crafted TrueType fonts. The flaw affects multiple Microsoft products including .NET Framework, Office, Lync, and Silverlight, allowing an attacker to execute arbitrary code if a user opens a specially crafted font file or visits a website with embedded fonts.
Affected products
- Microsoft DirectWrite
- Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2
- Microsoft Office 2007 SP3, 2010 SP2
- Microsoft Live Meeting 2007 Console
- Microsoft Lync 2010, 2010 Attendee, 2013 SP1, Basic 2013 SP1
- Microsoft Silverlight 5 before 5.1.40416.00
- Microsoft Silverlight 5 Developer Runtime before 5.1.40416.00
Timeline
- 2015-05-12: patched: Microsoft released security bulletin MS15-044 to address the issue.
- 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-05-25: disclosed