← All CVEs

CVE-2015-6106

high · 9.3

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

9.3
CVSS
17.3%
EPSS (exploit prob.)
97th
EPSS percentile
2015-12-09
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
microsoftlive_meeting2007
microsoftlync2010
microsoftlync2010
microsoftlync2013
microsoftoffice2007
microsoftoffice2010
microsoftoffice2010
microsoftskype_for_business2016
microsoftword_viewerall versions
microsoftwindows_server_2008all versions
microsoftwindows_vistaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-6106