A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
Hay una vulnerabilidad de ejecución de código remota en Microsoft Windows cuando la Windows Adobe Type Manager Library maneja inapropiadamente un formato Adobe Type 1 PostScript de una fuente multi-master especialmente diseñada. En todos los sistemas, excepto en Windows 10, un atacante que explotara con éxito la vulnerabilidad podría ejecutar código remotamente, también se conoce como "Adobe Font Manager Library Remote Code Execution Vulnerability". Este ID de CVE es diferente de CVE-2020-1020.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_10_1507 | - | <built-in method update of dict object at 0x7e60e8c7ef00> | Operating System |
| microsoft | windows_10_1507 | - | <built-in method update of dict object at 0x7e61114e0b80> | Operating System |
| microsoft | windows_10_1607 | - | <built-in method update of dict object at 0x7e613c4c3400> | Operating System |
| microsoft | windows_10_1607 | - | <built-in method update of dict object at 0x7e60bae4b580> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e60e8c7e8c0> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e60e8c7db40> | Operating System |
| microsoft | windows_10_1709 | - | <built-in method update of dict object at 0x7e6100e97a80> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e61114e0340> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e6108405ec0> | Operating System |
| microsoft | windows_10_1803 | - | <built-in method update of dict object at 0x7e60e8c7ea00> | Operating System |
| microsoft | windows_10_1809 | - | <built-in method update of dict object at 0x7e6108405740> | Operating System |
| microsoft | windows_10_1809 | - | <built-in method update of dict object at 0x7e61114e0c40> | Operating System |
| microsoft | windows_10_1809 | - | <built-in method update of dict object at 0x7e60e8c7ea80> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e611232ca40> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e61114e0500> | Operating System |
| microsoft | windows_10_1903 | - | <built-in method update of dict object at 0x7e61114e3200> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e6108406200> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e61114e3080> | Operating System |
| microsoft | windows_10_1909 | - | <built-in method update of dict object at 0x7e6100e95500> | Operating System |
| microsoft | windows_7 | - | <built-in method update of dict object at 0x7e6112c85900> | Operating System |
| microsoft | windows_8.1 | - | <built-in method update of dict object at 0x7e60bae4bf40> | Operating System |
| microsoft | windows_rt_8.1 | - | <built-in method update of dict object at 0x7e61114e1480> | Operating System |
| microsoft | windows_server_1803 | - | <built-in method update of dict object at 0x7e6108407ec0> | Operating System |
| microsoft | windows_server_1903 | - | <built-in method update of dict object at 0x7e6100e96ec0> | Operating System |
| microsoft | windows_server_1909 | - | <built-in method update of dict object at 0x7e60e88171c0> | Operating System |
| microsoft | windows_server_2008 | - | <built-in method update of dict object at 0x7e6100e973c0> | Operating System |
| microsoft | windows_server_2008 | r2 | <built-in method update of dict object at 0x7e60bae4aa40> | Operating System |
| microsoft | windows_server_2008 | r2 | <built-in method update of dict object at 0x7e6108405040> | Operating System |
| microsoft | windows_server_2012 | - | <built-in method update of dict object at 0x7e6100e94a80> | Operating System |
| microsoft | windows_server_2012 | r2 | <built-in method update of dict object at 0x7e6100e97900> | Operating System |
| microsoft | windows_server_2016 | - | <built-in method update of dict object at 0x7e6108405b80> | Operating System |
| microsoft | windows_server_2019 | - | <built-in method update of dict object at 0x7e6100e97d80> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:* |
| Yes | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |