Vulnerabilities > CVE-2015-6130 - Numeric Errors vulnerability in Microsoft Windows 7 and Windows Server 2008
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer underflow in Uniscribe in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows remote attackers to execute arbitrary code via a crafted font, aka "Windows Integer Underflow Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS15-130 |
bulletin_url | |
date | 2015-12-08T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 3108670 |
knowledgebase_url | |
severity | Critical |
title | Security Update for Microsoft Uniscribe to Address Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS15-130.NASL |
description | The remote Windows host is affected by a remote code execution vulnerability due to improper parsing of fonts by Uniscribe. A remote attacker can exploit this vulnerability by convincing a user to open a specially crafted document or visit an untrusted website that contains specially crafted embedded fonts, resulting in the execution of arbitrary code in the context of the current user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 87259 |
published | 2015-12-08 |
reporter | This script is Copyright (C) 2015-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/87259 |
title | MS15-130: Security Update for Microsoft Uniscribe to Address Remote Code Execution (3108670) |
code |
|
References
- http://blogs.flexerasoftware.com/secunia-research/2015/12/vulnerability-in-microsofts-unicode-scripts-processor-allows-execution-of-arbitrary-code.html
- http://blogs.flexerasoftware.com/secunia-research/2015/12/vulnerability-in-microsofts-unicode-scripts-processor-allows-execution-of-arbitrary-code.html
- http://www.securitytracker.com/id/1034337
- http://www.securitytracker.com/id/1034337
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-130
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-130