ZeroHour

CVE-2020-1020

KEVmass

Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library

CISA: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
65%p99
Published
()
KEV added
AI analysis

CVE-2020-1020 is a remote code execution vulnerability (out-of-bounds write, CWE-787) in the Adobe Font Manager Library shipped with Microsoft Windows, caused by improper handling of a specially crafted multi-master font in Adobe Type 1 PostScript format. Triggering it requires user interaction: an attacker delivers a malicious document or font, and the vulnerable code runs when the content is previewed or opened (no authentication is needed on the network path, but the user must interact). On all systems except Windows 10, successful exploitation allows the attacker to execute arbitrary code remotely in the context of the current user; on Windows 10 the flaw is present as well, with the full remote-code-execution impact described for non-Windows-10 systems. Affected software spans Windows 10 versions 1507 through 1909, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 1903/1909. The bug was exploited in the wild as a zero-day by a sophisticated threat actor prior to patching (CISA KEV, added 2021-11-03), and EPSS assigns a 65% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft's security update for CVE-2020-1020 via Windows Update (April 2020 Patch Tuesday cycle) on all Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1903/1909 hosts, per CISA's required action. As interim mitigation, disable the Explorer preview and details panes and avoid opening or previewing untrusted documents and fonts. Verify the fix is deployed, prioritizing non-Windows-10 systems where successful exploitation yields full remote code execution.

Affected
microsoft Windows 101507, 1607, 1709, 1803, 1809, 1903, 1909
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Server 19031903
microsoft Windows Server 19091909
Estimated exposure
masshundreds of millions of Windows client/server devices (OS component shipped in all listed Windows releases) — The vulnerable Adobe Font Manager Library ships with every affected Windows release, so exposure tracks the Windows installed base — Windows 7 alone ran on hundreds of millions of PCs in 2020 — with actual exploitation risk concentrated on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1903, windows server 1909
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news