
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15273 is a stack-based buffer overflow vulnerability in FontForge that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of PFB (Printer Font Binary) files, where user-supplied data length is not properly validated before being copied to a fixed-length stack-based buffer. It affects FontForge version 2025-11-17 and was publicly disclosed on December 29, 2025, as a zero-day advisory after the vendor rejected the report. The vulnerability carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-121 (Stack-based Buffer Overflow), stemming from the absence of proper length validation of user-supplied data during PFB file parsing before it is copied into a fixed-length stack-based buffer. An attacker exploits this by crafting a malicious PFB file or a web page that triggers FontForge to open such a file, causing a stack buffer overflow that can overwrite control flow data (e.g., return addresses). The precondition for exploitation is user interaction — the target must either visit a malicious page or open a malicious file. ZDI tracked this internally as ZDI-CAN-28546 and published the advisory as a 0-day after the vendor declined to address the report (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, potentially leading to full compromise of the affected system's confidentiality, integrity, and availability. An attacker could read sensitive files, modify data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The impact is constrained to the privileges of the user running FontForge, but on systems where FontForge is used in automated font processing pipelines, the blast radius could be broader (ZDI Advisory, Red Hat Bugzilla).
The ZDI published this as a zero-day advisory on December 29, 2025, after the FontForge vendor rejected the vulnerability report and declined to issue a fix. A proof-of-concept exploit reference is available via the ZDI advisory page, though detailed exploit code has not been publicly released. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.353%, reflecting a currently low but non-negligible probability of exploitation (ZDI Advisory).
/bin/bash, cmd.exe, powershell.exe, or network utilities like curl, wget).No official patch has been released by the FontForge vendor, who rejected the vulnerability report submitted by ZDI. The primary recommended mitigation is to restrict interaction with FontForge to only trusted, verified sources and avoid opening PFB files from unknown or untrusted origins. Organizations should consider disabling or restricting FontForge usage in automated pipelines until a fix is available. Users should monitor for a vendor-issued patch and apply it promptly upon release (ZDI Advisory, Red Hat Bugzilla).
The vulnerability received coverage from The Hacker Wire on social media platforms including Mastodon and Bluesky, highlighting the zero-day disclosure and the vendor's rejection of the report. The security community noted concern over the vendor's response — requiring submitters to provide a pull request with a fix rather than acknowledging the vulnerability — which led ZDI to publish the advisory as a 0-day. Red Hat opened a tracking bug (Bug 2426428) indicating downstream Linux distribution awareness and monitoring of the issue (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."