Vulnerability record · CVE-2015-2426 · published 20 July 2015
CVE-2015-2426: Windows Adobe Type Manager Library buffer underflow via crafted OpenType font
Microsoft · Windows 10
A buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing is reachable from ordinary document and web content, the flaw is a reliable remote code execution primitive on unpatched Windows systems.
Description
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remotely reachable, unauthenticated code execution flaw with public exploit code, KEV listing and very high EPSS, so unpatched hosts should be treated as actively at risk.
What it is
A buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing is reachable from ordinary document and web content, the flaw is a reliable remote code execution primitive on unpatched Windows systems.
Impact
An attacker who gets a victim to render a malicious font can execute arbitrary code in the context of the affected process, typically the logged-on user. That yields full compromise of confidentiality, integrity and availability on the host.
Attack surface
Reached over the network (AV:N) with no privileges required, but user interaction is required (UI:R) because the victim must open or view content that loads the crafted font. Any application that renders untrusted fonts, including browsers and document viewers, is a potential vector.
Exploitation
Listed in CISA KEV since 2022-03-28 with a required action to patch, and EPSS shows a 30-day probability of 0.8669 (99.7th percentile). References are tagged Exploit and include an Exploit-DB entry, indicating public exploit code exists.
What to do
- Apply the Microsoft MS15-078 security update on all affected Windows versions; this is the primary fix.
- Retire or isolate unsupported end-of-life systems such as Vista SP2, Server 2008 SP2 and Windows RT that cannot be patched.
- Block or restrict rendering of untrusted embedded fonts in browsers, email clients and document viewers where policy allows.
- Enforce least privilege so code execution lands in a low-privilege user context rather than an administrative one.
- Monitor vendor advisories and KEV status for any renewed exploitation activity against remaining unpatched hosts.
Detection
- Hunt for processes loading atmfd.dll while handling fonts from untrusted or unusual paths, especially browser and document viewer child processes.
- Alert on unexpected child processes, script interpreters or network connections spawned by font-rendering applications.
- Search endpoint telemetry for known exploit artifacts tied to the public Exploit-DB PoC and the Hacking Team leak reporting.
- Correlate crash reports in atmfd.dll with subsequent suspicious process creation on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2426 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-2426 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2426), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.