CVE-2020-1436
Severity
8.8HIGH
EPSS
13.3%
top 5.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 14
Latest updateMay 24
Description
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages13 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-g587-x8m2-frwg: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts↗2022-05-24
CVEList▶
CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts↗2020-07-14