CVE-2020-0938
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
CISA KEV
- Vendor
- Microsoft
- Product
- Windows
- Due date
- 2022-05-03
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2020-0938
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.