Junglewise Threat Intelligence

CVE-2020-0938: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-0938 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows 7, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows Server 2019, Microsoft Windows Server 2008, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft Windows Adobe Type Manager Library due to improper handling of specially crafted multi-master fonts in Adobe Type 1 PostScript format. On most Windows versions, successful exploitation allows full remote code execution, while on Windows 10, execution is restricted to an AppContainer sandbox context.

Affected products

  • Microsoft Windows 7 Service Pack 1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows 10 Versions 1507, 1607, 1709, 1803, 1809, 1903, 1909
  • Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows Server 2016 Gold, 1803, 1903, 1909
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 1803

Timeline

  • 2020-03-23: disclosed: Initial Microsoft advisory release date (implied by CVE year and KEV context)
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date

Related threats