CVE-2015-2461 is a critical remote code execution vulnerability affecting the ATMFD.DLL in the Adobe Type Manager Library across various Microsoft Windows versions, including Vista, 7, 8, 8.1, 10, and Server editions. This flaw allows attackers to execute arbitrary code by tricking users into opening a specially crafted OpenType font. With a CVSS score of 9.3, it is highly severe, requiring only medium attack complexity and leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (KEV), an exploit demonstrating an out-of-bounds read in ATMFD.DLL has been publicly disclosed on ExploitDB. Despite its severity and public exploit, community discussion and media coverage for this CVE are notably low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.