CVE-2020-1436
published 2020-07-14CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an…
PriorityP260high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
21.37%
97.3th percentile
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via specially crafted fonts embedded in documents or web pages; monitor for unusual font parsing activity in Windows font library (e.g., atmfd.dll / DirectWrite) ↗
- →Web-based delivery vector: users lured to attacker-controlled website hosting a malicious font; monitor web traffic and browser process spawning child processes ↗
- →File-sharing/email delivery vector: malicious document with embedded font sent as attachment; monitor for Office/PDF reader processes triggering font rendering followed by anomalous child process creation ↗
- →On Windows 10, successful exploitation results in code execution within an AppContainer sandbox; alert on AppContainer-sandboxed processes attempting privilege escalation or unusual outbound network connections ↗
- →Post-exploitation indicators include program installation, data modification/deletion, or new account creation; monitor for net user / useradd commands and file system changes following font rendering events ↗
- ·Exploitation likelihood is rated 'Less Likely' for both latest and older software releases by Microsoft; no public exploits or in-the-wild exploitation confirmed at time of advisory ↗
- ·Impact differs by OS version: non-Windows 10 systems allow full remote code execution, while Windows 10 limits execution to an AppContainer sandbox — detection and response priorities should be adjusted accordingly ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g587-x8m2-frwg: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts
ghsa_unreviewed·2022-05-24
CVE-2020-1436 [MEDIUM] CWE-20 GHSA-g587-x8m2-frwg: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
Microsoft
Windows Font Library Remote Code Execution Vulnerability
vendor_msrc·2020-07-14·CVSS 6.3
CVE-2020-1436 [HIGH] Windows Font Library Remote Code Execution Vulnerability
Windows Font Library Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.
For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vu
No detection rules found.
No public exploits indexed.
Krebs
‘Wormable’ Flaw Leads July Microsoft Patches
blogs_krebs·2020-07-14·CVSS 10.0
[CRITICAL] ‘Wormable’ Flaw Leads July Microsoft Patches
Microsoft today released updates to plug a whopping 123 security holes in Windows and related software, including fixes for a critical, “wormable” flaw in Windows Server versions that Microsoft says is likely to be exploited soon. While this particular weakness mainly affects enterprises, July’s care package from Redmond has a little something for everyone. So if you’re a Windows (ab)user, it’s time once again to back up and patch up (preferably in that order).
Microsoft said it is not aware of reports that anyone is exploiting the weakness (yet), but the flaw has been assigned a CVSS score of 10, which translates to “easy to attack” and “likely to be exploited.”
“We consider this to be a wormable vulnerability, meaning that it has the potential to spread via malware between vulnerable c
Trendmicro
Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
blogs_trendmicro·2020-07-14·CVSS 7.8
[HIGH] Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
# Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs were disclosed through Trend Micro’s Zero Day Initiative (ZDI) program.
By: Trend Micro
2020/07/14
Read time: ( words)
Save to Folio
There has been a common vulnerabilities and exposures (CVE) fixing trend in 2020 Patch Tuesdays. For instance, Microsoft has patched roughly more than 100 vulnerabilities per month in recent bulletins. Similarly, the July update issues 123 patches, including fixes in RemoteFX vGPU, Microsoft Office, Microsoft Windows, OneDrive, and Jet Database Engine.
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs wer
Krebs
‘Wormable’ Flaw Leads July Microsoft Patches
blogs_krebs·2020-07-14·CVSS 10.0
[CRITICAL] ‘Wormable’ Flaw Leads July Microsoft Patches
Microsoft today released updates to plug a whopping 123 security holes in Windows and related software, including fixes for a critical, “wormable” flaw in Windows Server versions that Microsoft says is likely to be exploited soon. While this particular weakness mainly affects enterprises, July’s care package from Redmond has a little something for everyone. So if you’re a Windows (ab)user, it’s time once again to back up and patch up (preferably in that order).
Top of the heap this month in terms of outright scariness is CVE-2020-1350 , which concerns a remotely exploitable bug in more or less all versions of Windows Server that attackers could use to install malicious software simply by sending a specially crafted DNS request.
Microsoft said it is not aware of reports that anyone is exp
http://www.openwall.com/lists/oss-security/2020/08/25/3http://www.openwall.com/lists/oss-security/2020/08/25/5https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1436https://www.zerodayinitiative.com/advisories/ZDI-20-877/http://www.openwall.com/lists/oss-security/2020/08/25/3http://www.openwall.com/lists/oss-security/2020/08/25/5https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1436https://www.zerodayinitiative.com/advisories/ZDI-20-877/
2020-07-14
Published