cbcvebase.
CVE-2020-0938
published 2020-04-15

CVE-2020-0938: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted…

PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
69.17%
99.3th percentile
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10_version_1903_for_32-bit_systems
microsoftwindows_10_version_1903_for_arm64-based_systems
microsoftwindows_10_version_1903_for_x64-based_systems
microsoftwindows_10_version_1909_for_32-bit_systems
microsoftwindows_10_version_1909_for_arm64-based_systems
microsoftwindows_10_version_1909_for_x64-based_systems
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector via Windows Explorer Preview Pane: viewing a specially crafted document containing a malicious Adobe Type 1 PostScript multi-master font in the Preview Pane triggers the vulnerability without user opening the file.
  • Windows Explorer Preview Pane (not Outlook Preview Pane) is a confirmed attack vector; monitor for font-parsing activity triggered by explorer.exe when previewing documents.
  • Exploitation confirmed in the wild with limited, targeted attacks; treat any suspicious OTF/Type1 font file opened via Explorer Preview as high-priority alert.
  • Monitor for presence and loading of ATMFD.DLL on pre-Windows 10 systems; unexpected loading of this DLL by non-font-rendering processes may indicate exploitation.
  • WebDAV/WebClient service abuse is the primary remote attack vector; monitor for WebClient service activity or WebDAV requests delivering crafted font documents.
  • CVE-2020-0938 and CVE-2020-1020 are both Adobe Font Manager Library RCE bugs; no confirmed link between their in-the-wild attack campaigns, but both should be treated as active threats.
  • ·ATMFD.DLL is absent from Windows 10 version 1709 and later; registry-based DisableATMFD workarounds and ATMFD.DLL renaming mitigations only apply to pre-Windows 10 systems.
  • ·On Windows 10, successful exploitation is sandboxed to an AppContainer context with limited privileges, reducing impact compared to all other Windows versions where full RCE is possible.
  • ·Enhanced Security Configuration (ESC), enabled by default on Windows Servers, does NOT mitigate this vulnerability.
  • ·Disabling the Preview/Details panes and WebClient service are partial mitigations only; they do not prevent exploitation if a user directly opens a specially crafted document.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.