Junglewise Threat Intelligence

CVE-2015-2387: Microsoft ATM Font Driver Privilege Escalation Vulnerability

CVE-2015-2387 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Server 2003, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability in ATMFD.DLL within the Adobe Type Manager Font Driver in Microsoft Windows allows local users to escalate privileges. An attacker can exploit this by running a specially crafted application to gain elevated system rights.

Affected products

  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8 Gold
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT Gold, 8.1

Timeline

  • 2015-07-14: patched: Microsoft released security bulletin MS15-077 to address this vulnerability.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: NVD publication date.