cbcvebase.
CVE-2020-1436
published 2020-07-14

CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an…

PriorityP260high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
21.37%
97.3th percentile
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via specially crafted fonts embedded in documents or web pages; monitor for unusual font parsing activity in Windows font library (e.g., atmfd.dll / DirectWrite)
  • Web-based delivery vector: users lured to attacker-controlled website hosting a malicious font; monitor web traffic and browser process spawning child processes
  • File-sharing/email delivery vector: malicious document with embedded font sent as attachment; monitor for Office/PDF reader processes triggering font rendering followed by anomalous child process creation
  • On Windows 10, successful exploitation results in code execution within an AppContainer sandbox; alert on AppContainer-sandboxed processes attempting privilege escalation or unusual outbound network connections
  • Post-exploitation indicators include program installation, data modification/deletion, or new account creation; monitor for net user / useradd commands and file system changes following font rendering events
  • ·Exploitation likelihood is rated 'Less Likely' for both latest and older software releases by Microsoft; no public exploits or in-the-wild exploitation confirmed at time of advisory
  • ·Impact differs by OS version: non-Windows 10 systems allow full remote code execution, while Windows 10 limits execution to an AppContainer sandbox — detection and response priorities should be adjusted accordingly

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.