4.3
CVE-2015-1670
- EPSS 16.09%
- Veröffentlicht 13.05.2015 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from process memory via a crafted OpenType font on a web site, aka "OpenType Font Parsing Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 3.0 Update sp2
Microsoft ≫ .Net Framework Version 3.5
Microsoft ≫ .Net Framework Version 3.5.1
Microsoft ≫ .Net Framework Version 4.0
Microsoft ≫ .Net Framework Version 4.5
Microsoft ≫ .Net Framework Version 4.5.1
Microsoft ≫ .Net Framework Version 4.5.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 16.09% | 0.965 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.securityfocus.com/bid/74485
http://www.securitytracker.com/id/1032281
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-044