SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2015-1671

HIGH · CVSS 7.8 EPSS 54.63% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-05-13 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Microsoft, Windows, Office. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Its EPSS score suggests a 54.6% probability of exploitation in the next 30 days. It may be remotely exploitable.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-05-25

Required action: Apply updates per vendor instructions.

CVE
CVE-2015-1671
Severity
HIGH
CVSS
7.8
EPSS
54.63%
Microsoft Windows Office

Original NVD Description

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability."