CVE-2015-2456 (CNNVD-201508-166)
中文标题:
Microsoft TrueType字体分析漏洞
英文标题:
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8...
漏洞描述
中文描述:
Microsoft Windows、.NET Framework、Office、Lync和Silverlight都是美国微软(Microsoft)公司发布的产品。Windows是一系列操作系统。.NET Framework是一种全面且一致的编程模型。Office是一款办公软件套件产品。Lync是新一代企业整合沟通平台(前身为Communications Server)。Silverlight是一个功能强大的开发平台。 多款Microsoft产品的组件中存在远程执行代码漏洞,该漏洞源于程序没有正确处理TrueType字体。成功利用这些漏洞的攻击者可以完全控制受影响的系统。以下产品及版本受到影响:Microsoft Windows Vista SP2,Windows Server 2008 SP2和R2 SP1,Windows 7 SP1,Windows 8,Windows 8.1,Windows Server 2012 Gold和R2,Windows RT Gold和8.1,Windows 10,Office 2007 SP3和2010 SP2,Live Meeting 2007 Console,Lync 2010,Lync 2010 Attendee,Lync 2013 SP1,Lync Basic 2013 SP1,Silverlight 5.1.40728之前版本,.NET Framework 3.0 SP2,3.5,3.5.1,4,4.5,4.5.1, 4.5.2,4.6。
英文描述:
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2455.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | .net_framework | 3.0 | - | - |
cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*
|
| microsoft | .net_framework | 4.0 | - | - |
cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 4.5 | - | - |
cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 4.5.1 | - | - |
cpe:2.3:a:microsoft:.net_framework:4.5.1:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 4.5.2 | - | - |
cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 4.6 | - | - |
cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 3.5.1 | - | - |
cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
|
| microsoft | .net_framework | 3.5 | - | - |
cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
|
| microsoft | live_meeting | 2007 | - | - |
cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*
|
| microsoft | lync | 2010 | - | - |
cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*
|
| microsoft | lync | 2013 | - | - |
cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*
|
| microsoft | lync_basic | 2013 | - | - |
cpe:2.3:a:microsoft:lync_basic:2013:sp1:*:*:*:*:*:*
|
| microsoft | office | 2007 | - | - |
cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*
|
| microsoft | office | 2010 | - | - |
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
|
| microsoft | silverlight | * | - | - |
cpe:2.3:a:microsoft:silverlight:*:*:*:*:*:*:*:*
|
| microsoft | windows_10 | - | - | - |
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
|
| microsoft | windows_7 | - | - | - |
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
|
| microsoft | windows_8 | - | - | - |
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
|
| microsoft | windows_8.1 | - | - | - |
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
|
| microsoft | windows_rt | - | - | - |
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
|
| microsoft | windows_rt_8.1 | - | - | - |
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | r2 | - | - |
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
|
| microsoft | windows_server_2012 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
|
| microsoft | windows_server_2012 | r2 | - | - |
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
|
| microsoft | windows_vista | - | - | - |
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2015-2456 |
2025-11-11 15:18:55 | 2025-11-11 07:34:01 |
| NVD | nvd_CVE-2015-2456 |
2025-11-11 14:54:51 | 2025-11-11 07:42:43 |
| CNNVD | cnnvd_CNNVD-201508-166 |
2025-11-11 15:09:35 | 2025-11-11 07:52:09 |
| EXPLOITDB | exploitdb_EDB-37918 |
2025-11-11 15:05:50 | 2025-11-11 08:35:44 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 4 -> 7
- tags_count: 0 -> 3
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201508-166
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 26
- data_sources: ['cve'] -> ['cve', 'nvd']