cbcvebase.
CVE-2020-15999
published 2020-11-03

CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

PriorityP188critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
50.63%
98.8th percentile
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfreetype< freetype 2.10.2+dfsg-4 (bookworm)freetype 2.10.2+dfsg-4 (bookworm)
fedoraprojectfedora
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 0 < 2.10.2+dfsg-42.10.2+dfsg-4
freetypefreetype>= 2.6.0 < 2.10.42.10.4
googleandroid
googlechrome< 86.0.4240.11186.0.4240.111
googlechrome>= unspecified < 86.0.4240.11186.0.4240.111
googlechrome_chrome
mozillafirefox
msrccbl2_freetype_2.11.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_freetype_2.11.1-1_on_cbl_mariner_1.0
opensusebackports_sle
platformexternal_freetype>= 10:0 < 10:2021-01-0110:2021-01-01
platformexternal_freetype>= 11:0 < 11:2021-01-0111:2021-01-01
platformexternal_freetype>= 8.0:0 < 8.0:2021-01-018.0:2021-01-01
platformexternal_freetype>= 8.1:0 < 8.1:2021-01-018.1:2021-01-01
platformexternal_freetype>= 9:0 < 9:2021-01-019:2021-01-01

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-15999 (FreeType heap buffer overflow in Chrome) is chained with CVE-2020-17087 (Windows Kernel Cryptography Driver cng.sys privilege escalation) to escape the Chrome sandbox and gain administrative privileges
  • Post-exploitation reconnaissance uses nltest to discover domain controllers — monitor for nltest execution on endpoints
  • Post-exploitation domain enumeration uses 'net group /domain' — monitor for this command on endpoints
  • Post-exploitation local admin discovery uses 'net localgroup' — monitor for this command on endpoints
  • Post-exploitation service principal discovery uses setspn — monitor for setspn execution on endpoints
  • Post-exploitation SMB share discovery uses 'net use' and 'net share' — monitor for these commands on endpoints
  • The exploit targets the FreeType font rendering library included with Chrome; delivery vector is a crafted HTML page triggering heap corruption
  • CVE-2020-17087 abuses the Windows Kernel Cryptography Driver (cng.sys) DeviceCNG device via IOCTL — monitor for unusual user-mode access to cng.sys
  • ·Exploit was observed in the wild as a zero-day prior to the Chrome 86.0.4240.111 patch; unpatched Chrome versions below this are vulnerable

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa9.6CRITICAL
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_redhat9.6CRITICAL
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.