Junglewise Threat Intelligence

CVE-2020-1020: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-1020 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2016, Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 7, Microsoft Windows Server 2012, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft Windows Adobe Type Manager Library due to improper handling of specially crafted multi-master fonts in Adobe Type 1 PostScript format. On most Windows versions, this allows full remote code execution, while on Windows 10, execution is limited to an AppContainer sandbox context.

Affected products

  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 1803, 1903, 1909
  • Microsoft Windows Server 2019

Timeline

  • 2020-04-15: disclosed: Initial disclosure/analysis date recorded by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV and advisory report

Related threats