⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..

CVE-2020-1020Out-of-bounds Write in Microsoft Windows

Severity
8.8HIGHNVD
CNA7.8
EPSS
85.7%
top 0.62%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 15
KEV addedNov 3
KEV dueMay 3
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Patches

🔴Vulnerability Details

9
GHSA
GHSA-jvx5-6596-c2vj: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m2022-05-24
Project0
In-the-Wild Series: Windows Exploits - Project Zero2021-01-01
Project0
Introducing the In-the-Wild Series - Project Zero2021-01-01
CVEList
CVE-2020-1020: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m2020-04-15
VulnCheck
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability2020

📋Vendor Advisories

2
CISA
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability2021-11-03
Microsoft
Adobe Font Manager Library Remote Code Execution Vulnerability2020-04-14

🕵️Threat Intelligence

2
Krebs
Microsoft Patch Tuesday, April 2020 Edition2020-04-14
Krebs
Microsoft Patch Tuesday, April 2020 Edition2020-04-14
CVE-2020-1020 — Out-of-bounds Write in Microsoft | cvebase