Vulnerabilities > CVE-2015-2387 - Out-of-bounds Write vulnerability in Microsoft products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
microsoft
CWE-787
nessus

Summary

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."

Common Weakness Enumeration (CWE)

Msbulletin

bulletin_idMS15-077
bulletin_url
date2015-07-14T00:00:00
impactElevation of Privilege
knowledgebase_id3077657
knowledgebase_url
severityImportant
titleVulnerability in ATM Font Driver Could Allow Elevation of Privilege

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS15-077.NASL
descriptionThe remote Windows host is affected by a privilege escalation vulnerability in the Adobe Type Manager Font Driver (ATMFD) due to a failure to properly handle objects in memory. A local attacker can exploit this by running a specially crafted application, resulting in arbitrary code execution with elevated privileges.
last seen2020-06-01
modified2020-06-02
plugin id84746
published2015-07-14
reporterThis script is Copyright (C) 2015-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/84746
titleMS15-077: Vulnerability in ATM Font Driver Could Allow Elevation of Privilege (3077657)