← Vulnerability feed

Vulnerability record · CVE-2015-1671 · published 13 May 2015

CVE-2015-1671: Microsoft DirectWrite TrueType Font Parsing Remote Code Execution

Microsoft · .Net Framework

The Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including .NET Framework, Office, Lync, Live Meeting, and Silverlight. Because fonts are commonly processed automatically, this is a serious risk for unpatched systems.

7.8 CVSS 3.1 High CISA KEV since 25 May 2022 EPSS 49% · top 1.2%
7.8CVSS 3.1 base score, v2 9.3
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe vulnerability is listed in CISA KEV, has a high EPSS score, and allows remote code execution with user interaction, making it a high-priority target for attackers.

What it is

The Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including .NET Framework, Office, Lync, Live Meeting, and Silverlight. Because fonts are commonly processed automatically, this is a serious risk for unpatched systems.

Impact

An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could take complete control of the affected system.

Attack surface

The vulnerability is reached when a user opens or previews a document, webpage, or application that renders a malicious TrueType font. User interaction is required, and no authentication is needed to trigger the flaw.

Exploitation

CVE-2015-1671 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS estimates a 54.6% probability of exploitation in the next 30 days, placing it in the 98.9th percentile.

What to do

  • Apply the vendor patch referenced in Microsoft Security Bulletin MS15-044 immediately.
  • Disable or restrict the use of untrusted TrueType fonts where feasible.
  • Implement application whitelisting to block execution of untrusted binaries.
  • Educate users to avoid opening suspicious documents or visiting untrusted websites.
  • Monitor for and block known malicious font files at email and web gateways.

Detection

  • Monitor for process creation events involving font rendering libraries (e.g., DirectWrite) loading unusual files.
  • Scan for known malicious TrueType font files using updated antivirus signatures.
  • Audit systems for missing MS15-044 patches using vulnerability management tools.
  • Enable and review Windows Defender Exploit Guard or similar memory protection logs for anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-1671 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1671 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-0646Microsoft .NET Framework input validation flaw enables remote code executionCVE-2020-0646 is a critical remote code execution vulnerability in the Microsoft .NET Framework caused by improper input validation, classified as XM…KEVEPSS 99%analysed8.8CVE-2016-0034Microsoft Silverlight negative offset decoding flaw allows remote code executionMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this…KEVEPSS 69%analysed7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed7.8CVE-2017-8759Microsoft .NET Framework remote code execution via malicious documentMicrosoft .NET Framework versions 2.0 through 4.7 contain a code injection flaw that lets an attacker run arbitrary code when a crafted document or a…KEVEPSS 89%analysed7.8CVE-2013-3906Microsoft GDI+ TIFF parsing code execution via crafted imageGDI+ in multiple Microsoft products fails to properly handle crafted TIFF images, allowing memory corruption that leads to arbitrary code execution. …KEVEPSS 85%analysed7.8CVE-2013-0074Microsoft Silverlight pointer validation flaw enables remote code executionMicrosoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Sil…KEVEPSS 79%analysed7.5CVE-2024-29059Microsoft .NET Framework error message information disclosureCVE-2024-29059 is an information disclosure flaw in Microsoft .NET Framework, classified as CWE-209 (error message information leak). A remote, unaut…KEVEPSS 99%analysed5.5CVE-2013-3896Microsoft Silverlight pointer validation flaw leaks sensitive informationMicrosoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight …KEVEPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2015-1671), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.