CVE-2015-2464
Microsoft Windows Vista SP2、Windows Server 2008 SP2 および R2 SP1、Windows 7 SP1、Windows 8、Windows 8.1、Windows Server 2012 Gold および R2、Windows RT Gold および...
- 公開済み
- 2015/08/15
- 更新済み
- 2024/08/06
- CNA の割り当て
- microsoft
- 観察された証拠
- 2015/08/21
プライマリ CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C中 · 今後 30 日間
- パーセンタイル
- 98.4%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Microsoft Windows Vista SP2、Windows Server 2008 SP2 および R2 SP1、Windows 7 SP1、Windows 8、Windows 8.1、Windows Server 2012 Gold および R2、Windows RT Gold および 8.1、Office 2007 SP3 および 2010 SP2、Live Meeting 2007 Console、Lync 2010、Lync 2010 Attendee、Lync 2013 SP1、Lync Basic 2013 SP1、5.1.40728 より前の Silverlight、および .NET Framework 3.0 SP2、3.5、3.5.1、4、4.5、4.5.1、4.5.2、4.6 には、リモートの攻撃者が巧妙に細工された TrueType フォントを介して任意のコードを実行できる脆弱性が存在します。これは別名「TrueType フォント解析の脆弱性」として知られ、CVE-2015-2463 とは異なる脆弱性です。
ソース
1- Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Writeエクスプロイト
Google Security Research · windows · 2015/08/21
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。