← Vulnerability feed

Vulnerability record · CVE-2015-2426 · published 20 July 2015

CVE-2015-2426: Windows Adobe Type Manager Library buffer underflow via crafted OpenType font

Microsoft · Windows 10

A buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing is reachable from ordinary document and web content, the flaw is a reliable remote code execution primitive on unpatched Windows systems.

8.8 CVSS 3.1 High CISA KEV since 28 Mar 2022 EPSS 87% · top 0.3% CWE-119 · Memory buffer overflowCWE-124 · CWE-124
8.8CVSS 3.1 base score, v2 9.3
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a remotely reachable, unauthenticated code execution flaw with public exploit code, KEV listing and very high EPSS, so unpatched hosts should be treated as actively at risk.

What it is

A buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing is reachable from ordinary document and web content, the flaw is a reliable remote code execution primitive on unpatched Windows systems.

Impact

An attacker who gets a victim to render a malicious font can execute arbitrary code in the context of the affected process, typically the logged-on user. That yields full compromise of confidentiality, integrity and availability on the host.

Attack surface

Reached over the network (AV:N) with no privileges required, but user interaction is required (UI:R) because the victim must open or view content that loads the crafted font. Any application that renders untrusted fonts, including browsers and document viewers, is a potential vector.

Exploitation

Listed in CISA KEV since 2022-03-28 with a required action to patch, and EPSS shows a 30-day probability of 0.8669 (99.7th percentile). References are tagged Exploit and include an Exploit-DB entry, indicating public exploit code exists.

What to do

  • Apply the Microsoft MS15-078 security update on all affected Windows versions; this is the primary fix.
  • Retire or isolate unsupported end-of-life systems such as Vista SP2, Server 2008 SP2 and Windows RT that cannot be patched.
  • Block or restrict rendering of untrusted embedded fonts in browsers, email clients and document viewers where policy allows.
  • Enforce least privilege so code execution lands in a low-privilege user context rather than an administrative one.
  • Monitor vendor advisories and KEV status for any renewed exploitation activity against remaining unpatched hosts.

Detection

  • Hunt for processes loading atmfd.dll while handling fonts from untrusted or unusual paths, especially browser and document viewer child processes.
  • Alert on unexpected child processes, script interpreters or network connections spawned by font-rendering applications.
  • Search endpoint telemetry for known exploit artifacts tied to the public Exploit-DB PoC and the Hacking Team leak reporting.
  • Correlate crash reports in atmfd.dll with subsequent suspicious process creation on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-2426 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2015-2426), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.