Severity
8.8HIGH
EPSS
13.3%
top 5.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g587-x8m2-frwg: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts2022-05-24
CVEList
CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts2020-07-14

📋Vendor Advisories

1
Microsoft
Windows Font Library Remote Code Execution Vulnerability2020-07-14
CVE-2020-1436 (HIGH CVSS 8.8) | A remote code execution vulnerabili | cvebase.io