CVE-2020-0938
KEVmassOut-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library
CISA: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
CVE-2020-0938 is an out-of-bounds write (CWE-787) in the Windows Adobe Type Manager (Adobe Font Manager) Library, the Windows component that renders Adobe Type 1 PostScript fonts. It is triggered when the library improperly handles a specially crafted multi-master Adobe Type 1 PostScript font, typically when a user opens or previews a document or file containing the malicious font; the CVSS vector requires user interaction, and Microsoft notes that on systems other than Windows 10 the code execution can be achieved remotely. A successful attack lets the attacker execute arbitrary code with the privileges of the current user. Affected systems include Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server versions 1803 and 1903, which together covered essentially the entire supported Windows install base in early 2020. Microsoft patched the flaw as one of three Windows zero-days actively exploited at the April 2020 Patch Tuesday, public reporting (including from Google) described a sophisticated hacking campaign using 11 different zero-days involving these Windows font bugs, and CISA added the CVE to its Known Exploited Vulnerabilities catalog in November 2021; EPSS estimates a 69% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known.
What to do: Apply the April 2020 Microsoft security updates (or later cumulative updates) to every affected Windows and Windows Server version, per Microsoft's instructions, and verify that end-of-life Windows 7, 8.1 and RT 8.1 machines received the final patches. Until systems are patched, reduce exposure using Microsoft's published mitigations: disable File Explorer's Preview and Details panes (a documented attack vector) and, for remote exploitation scenarios, the WebClient service, and caution users against opening or previewing untrusted documents and fonts. Check asset inventories for remaining Windows 7/8.1/RT 8.1 and Windows 10 1507–1909 builds, which no longer receive updates.
| microsoft Windows 10 (version 1507) | 1507 |
| microsoft Windows 10 (version 1607) | 1607 |
| microsoft Windows 10 (version 1709) | 1709 |
| microsoft Windows 10 (version 1803) | 1803 |
| microsoft Windows 10 (version 1809) | 1809 |
| microsoft Windows 10 (version 1903) | 1903 |
| microsoft Windows 10 (version 1909) | 1909 |
| microsoft Windows 7 | all supported releases at disclosure (no service pack specified in source data) |
| microsoft Windows 8.1 | all supported releases at disclosure |
| microsoft Windows RT 8.1 | all supported releases at disclosure |
| microsoft Windows Server, version 1803 | 1803 |
| microsoft Windows Server, version 1903 | 1903 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H