Microsoft released security bulletin MS15-010 to fix six vulnerabilities in the Windows kernel-mode driver and related components, including the critical remote code execution flaw CVE-2015-0059 in Win32k.sys. The bug could let an attacker run code if a user opened a specially crafted document or visited an untrusted website containing embedded TrueType fonts. Microsoft rated the update Critical for supported editions of Windows 7, Windows Server 2008 R2, Windows 8, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows RT, and Windows RT 8.1, and Important for supported editions of Windows Server 2003, Windows Vista, and Windows Server 2008.
The bulletin also addressed elevation of privilege, security feature bypass, and denial of service issues, including one publicly disclosed vulnerability, CVE-2015-0010, and five privately reported flaws. Microsoft said none of the vulnerabilities were known to be under active exploitation at publication, and said the fixes strengthened parameter validation, impersonation enforcement, object handling, user-mode data validation, TrueType font error checking, and font width checks. The company separately clarified that update 3037639 was a non-security fix for text quality degradation caused by update 3013455 on some older Windows versions and was not required for security protection.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On February 18, 2015, Microsoft updated the MS15-010 bulletin. The bulletin noted that one flaw, CVE-2015-0010, had been publicly disclosed, while Microsoft said none of the vulnerabilities were known to be actively exploited at the time of publication.
On February 10, 2015, Microsoft released security bulletin MS15-010 (3036220) to address six vulnerabilities in the Windows kernel-mode driver and related components. The bulletin rated the update Critical for several supported Windows client and server versions and Important for older supported platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcetechnet.microsoft.com
Open sourcego.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.