CVE-2015-6103
Microsoft Windows - Remote Code Execution via Crafted Embedded Font
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-6103. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a pool corruption vulnerability in the Windows kernel (win32k.sys) triggered by a malformed TTF font file. The issue occurs during font processing, leading to a PAGE_FAULT_IN_NONPAGED_AREA crash, and is reproducible on Windows 7 (32/64-bit).
Description
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6104.
Exploits (1)
This exploit demonstrates a pool corruption vulnerability in the Windows kernel (win32k.sys) triggered by a malformed TTF font file. The issue occurs during font processing, leading to a PAGE_FAULT_IN_NONPAGED_AREA crash, and is reproducible on Windows 7 (32/64-bit).