KB3013455 (MS15-010) causes font corruption

Anonymous
2015-02-10T21:06:56+00:00

February 2015 update KB3013455 causes 'Courier New' font corruption on some Windows systems, I can confirm it for Windows Server 2003 and 2008. You can verify it in Notepad. Removing the update fixes the issue.

Windows 7 and 8.1 are not affected by the update.

[removed information that 64bit may not be affected]

Windows for home | Other | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2015-02-12T05:17:15+00:00

Yes Remove/Add Program >> View Installed Windows Updates >> I added the column to display installation date, reverse sorted and found "3013455" ((this update), then Uninstalled it.

This was common in the late 90's/early 2000's, had to remember which updates not to install that would break things. It's been solid for at least a decade, now this.

I don't really care what the fix is for. If I can't read my screen from my chair, I need to resolve it to do my job (own a web design firm).

I share the same opinion as this article "...the bottom line here is that if you want to be able to actually read the screen, you'll want to hold off installing this update until the problem is fixed."

http://windowsitpro.com/msrc/patch-tuesday-font-corruption-kb3013455

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2015-02-18T18:42:43+00:00

The link for all downloads is:

http://www.microsoft.com/en-us/search/Results.aspx?q=kb3013455&form=DLC

Choose your OS from the half dozen big options at the top and it brings you right to the download page.

Hit the big red download button and it should offer you two updates:

kb3013455   (the original that breaks fonts)

and

KB3037639  (the secondary update to fix fonts)

I installed the original, said do not reboot, and installed the second.

After reboot I appear patched and my fonts are good.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

300 additional answers

Sort by: Oldest
  1. Anonymous
    2015-02-12T12:12:41+00:00

    In my opinion these embedded fonts are a real plague. I think most "designers" of these sites are not simply aware that they require a font or simply do not care about extra download cost for nothing. 

    I agree, unfortunately the number of such sites has increased last year noticeably over here (including internet banking ones). Some of them are useless without the embedded fonts enabled because of missing small button icons.

    What would help is to preprocess the embedded font in user mode mode so it will have the same restrictions as the application (browser). Under standard user account and proper Software Restriction Policy settings I would consider it safe. Unfortunately it does not help now since the font binary format is processed in kernel mode with all consequences regarding security :-/

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-02-12T12:14:35+00:00

    You *are* losing an important security update, yes. Unfortunately. That's obviously the reason why this update was released with know issues. Just read the bulletin.

    https://technet.microsoft.com/en-us/library/security/MS15-010 Read down below the severity ratings table and then the Vulnerability Information. Some of the issues are marked Critical and have no mitigation.

    However, apparently the most critical issues that affect fonts are "not applicable" to exactly those systems that are affected by the rendering problem it seems (e.g. to Vista). It seems that these fixes get deployed in the 3013455 update on all systems although they are not necessary on all systems. Unfortunately, you cannot just install "half of the patch".

    There may have been good reasons to do that. For one, the CVE numbers for these are all from this year = quite new and maybe already exploited. It's possible that some of the other (necessary) fixes are based on fixes that are not necessary for these systems, so you need all of them or nothing.

    I strongly urge anyone not installing or uninstalling this patch to reflect what he's doing and read the bulletin, lower section, so he understands the ramifications.

    According to my understanding, if you uninstall this patch you lose two critical fixes that are not applicable to those systems and two important and one moderate fix that *are* applicable.

    (Btw, I've moved this issue from Windows 7 to Vista as it doesn't seem to affect newer systems.)

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-02-12T12:24:29+00:00

     

    If anyone does not install this patch I heartily recommend switching embedded fonts in the browser off. At least in IE that's easy. As others have mentioned the rendering problem seems to affect only certain fonts. So, a better solution might be to install this patch and use a different font than Courier New (unless it turns out that too many fonts are affected, I don't know).

    The issue described in the security bulletin is serious and you do not want to stay that open!

    I use Chrome, and that is certainly affected by this faulty patch, as is Firefox.

    I'd welcome suggestions for changes of font - at present Arial, Times New Roman and Courier New are defaults.

    I have asked before (and notice the post with the question has vanished) - why is this patch still being offered when it is known to cause issues with many users?

    Was this answer helpful?

    0 comments No comments