CVE-2020-1020: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.
Other sources
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1020?
CVE-2020-1020 is rated as Critical due to its potential for remote code execution.
How do I fix CVE-2020-1020?
To fix CVE-2020-1020, apply the latest security updates provided by Microsoft for your affected Windows version.
Which versions of Windows are affected by CVE-2020-1020?
CVE-2020-1020 affects various versions of Microsoft Windows, excluding Windows 10.
What type of vulnerability is CVE-2020-1020?
CVE-2020-1020 is a remote code execution vulnerability in the Windows Adobe Type Manager Library.
How can an attacker exploit CVE-2020-1020?
An attacker can exploit CVE-2020-1020 by crafting a specially-designed multi-master font to execute arbitrary code.