ZeroHour

CVE-2020-0938

KEVmass

Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library

CISA: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
69%p99
Published
()
KEV added
AI analysis

CVE-2020-0938 is an out-of-bounds write (CWE-787) in the Windows Adobe Type Manager (Adobe Font Manager) Library, the Windows component that renders Adobe Type 1 PostScript fonts. It is triggered when the library improperly handles a specially crafted multi-master Adobe Type 1 PostScript font, typically when a user opens or previews a document or file containing the malicious font; the CVSS vector requires user interaction, and Microsoft notes that on systems other than Windows 10 the code execution can be achieved remotely. A successful attack lets the attacker execute arbitrary code with the privileges of the current user. Affected systems include Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server versions 1803 and 1903, which together covered essentially the entire supported Windows install base in early 2020. Microsoft patched the flaw as one of three Windows zero-days actively exploited at the April 2020 Patch Tuesday, public reporting (including from Google) described a sophisticated hacking campaign using 11 different zero-days involving these Windows font bugs, and CISA added the CVE to its Known Exploited Vulnerabilities catalog in November 2021; EPSS estimates a 69% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known.

What to do: Apply the April 2020 Microsoft security updates (or later cumulative updates) to every affected Windows and Windows Server version, per Microsoft's instructions, and verify that end-of-life Windows 7, 8.1 and RT 8.1 machines received the final patches. Until systems are patched, reduce exposure using Microsoft's published mitigations: disable File Explorer's Preview and Details panes (a documented attack vector) and, for remote exploitation scenarios, the WebClient service, and caution users against opening or previewing untrusted documents and fonts. Check asset inventories for remaining Windows 7/8.1/RT 8.1 and Windows 10 1507–1909 builds, which no longer receive updates.

Affected
microsoft Windows 10 (version 1507)1507
microsoft Windows 10 (version 1607)1607
microsoft Windows 10 (version 1709)1709
microsoft Windows 10 (version 1803)1803
microsoft Windows 10 (version 1809)1809
microsoft Windows 10 (version 1903)1903
microsoft Windows 10 (version 1909)1909
microsoft Windows 7all supported releases at disclosure (no service pack specified in source data)
microsoft Windows 8.1all supported releases at disclosure
microsoft Windows RT 8.1all supported releases at disclosure
microsoft Windows Server, version 18031803
microsoft Windows Server, version 19031903
Estimated exposure
mass≈1 billion+ devices (affected versions spanned virtually the entire supported Windows client and Windows Server install base at disclosure in 2020) — The affected product list covers every Windows client and Windows Server (Semi-Annual Channel) version Microsoft supported at the time, when Windows was estimated to run on over a billion devices worldwide; because exploitation requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news