CVE-2020-0938: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
Other sources
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0938?
CVE-2020-0938 has a critical severity rating, allowing for remote code execution.
How do I fix CVE-2020-0938?
To fix CVE-2020-0938, apply the security updates provided by Microsoft for affected Windows versions.
Which versions of Windows are affected by CVE-2020-0938?
CVE-2020-0938 affects multiple versions of Windows, including Windows 7, Windows 8.1, Windows 10, and various Windows Server editions.
What could an attacker do if they exploit CVE-2020-0938?
An attacker who exploits CVE-2020-0938 can execute arbitrary code on the victim's machine with elevated privileges.
Is CVE-2020-0938 specific to a certain type of file?
Yes, CVE-2020-0938 specifically relates to vulnerabilities in the handling of specially-crafted multi-master fonts.