Vulnerability record · CVE-2015-1671 · published 13 May 2015
CVE-2015-1671: Microsoft DirectWrite TrueType Font Parsing Remote Code Execution
Microsoft · .Net Framework
The Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including .NET Framework, Office, Lync, Live Meeting, and Silverlight. Because fonts are commonly processed automatically, this is a serious risk for unpatched systems.
Description
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is listed in CISA KEV, has a high EPSS score, and allows remote code execution with user interaction, making it a high-priority target for attackers.
What it is
The Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution. The flaw affects a wide range of Microsoft products including .NET Framework, Office, Lync, Live Meeting, and Silverlight. Because fonts are commonly processed automatically, this is a serious risk for unpatched systems.
Impact
An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could take complete control of the affected system.
Attack surface
The vulnerability is reached when a user opens or previews a document, webpage, or application that renders a malicious TrueType font. User interaction is required, and no authentication is needed to trigger the flaw.
Exploitation
CVE-2015-1671 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS estimates a 54.6% probability of exploitation in the next 30 days, placing it in the 98.9th percentile.
What to do
- Apply the vendor patch referenced in Microsoft Security Bulletin MS15-044 immediately.
- Disable or restrict the use of untrusted TrueType fonts where feasible.
- Implement application whitelisting to block execution of untrusted binaries.
- Educate users to avoid opening suspicious documents or visiting untrusted websites.
- Monitor for and block known malicious font files at email and web gateways.
Detection
- Monitor for process creation events involving font rendering libraries (e.g., DirectWrite) loading unusual files.
- Scan for known malicious TrueType font files using updated antivirus signatures.
- Audit systems for missing MS15-044 patches using vulnerability management tools.
- Enable and review Windows Defender Exploit Guard or similar memory protection logs for anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1671 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Windows Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/74490 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032281 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/74490 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032281 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1671 | US Government Resource |
Track CVE-2015-1671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1671), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.