Microsoft Silverlight < 5.1.41105.0 Multiple Vulnerabilities (MS15-128) (Mac OS X)

High Nessus Plugin ID 87250


A multimedia application framework installed on the remote Mac OS X host is affected by multiple vulnerabilities.


The version of Microsoft Silverlight installed on the remote host is affected by multiple remote code execution vulnerabilities due to improper handling of embedded fonts by the Windows font library. A remote attacker can exploit these by convincing a user to open a file or visit a website containing a specially crafted embedded font, resulting in execution of arbitrary code in the context of the current user.


Microsoft has released a set of patches for Silverlight 5.

See Also

Plugin Details

Severity: High

ID: 87250

File Name: macosx_ms15-128.nasl

Version: Revision: 1.4

Type: local

Agent: macosx

Published: 2015/12/08

Updated: 2017/08/30

Dependencies: 58091

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:microsoft:silverlight

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, MacOSX/Silverlight/Installed

Patch Publication Date: 2015/12/08

Vulnerability Publication Date: 2015/12/08

Reference Information

CVE: CVE-2015-6106, CVE-2015-6107, CVE-2015-6108

MSFT: MS15-128

IAVA: 2015-A-0308

MSKB: 3106614