CVE-2015-2426 — Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
CVE-2015-2426: Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Windows |
| Date added | 2022-03-28 |
| Due date | 2022-04-18 |
| Ransomware campaign use | Unknown |
Description
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2015-2426
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2015-2426
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog