AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-1671

HIGH · CVSS 7.8 EPSS 54.63% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-05-13 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Cross-Reference — CISA KEV

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-05-25

Required action: Apply updates per vendor instructions.

CVE
CVE-2015-1671
Severity
HIGH
CVSS
7.8
EPSS
54.63%
Microsoft Windows Office

Original Filing — NVD Description

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."