IM
IronMonkey Threat Research

CVE-2020-1020 HIGH

Published: 2020-04-15 | Last Modified: 2025-10-29 | Status: Analyzed

Description

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.

Additional Descriptions (1)

Hay una vulnerabilidad de ejecución de código remota en Microsoft Windows cuando la Windows Adobe Type Manager Library maneja inapropiadamente un formato Adobe Type 1 PostScript de una fuente multi-master especialmente diseñada. En todos los sistemas, excepto en Windows 10, un atacante que explotara con éxito la vulnerabilidad podría ejecutar código remotamente, también se conoce como "Adobe Font Manager Library Remote Code Execution Vulnerability". Este ID de CVE es diferente de CVE-2020-0938.

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 5.9

Base Score: 6.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-787

Affected Products

Vendor Product Version Update Type
microsoft windows_10_1507 - <built-in method update of dict object at 0x7e60a8a56340> Operating System
microsoft windows_10_1507 - <built-in method update of dict object at 0x7e60a8a57740> Operating System
microsoft windows_10_1607 - <built-in method update of dict object at 0x7e60a8a57e80> Operating System
microsoft windows_10_1709 - <built-in method update of dict object at 0x7e60a8a546c0> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e60a8a57a40> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e60a8a559c0> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e60e8816380> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e60a8a56940> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e60a88aa9c0> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e60a8a543c0> Operating System
microsoft windows_10_1903 - <built-in method update of dict object at 0x7e61114e2e00> Operating System
microsoft windows_10_1903 - <built-in method update of dict object at 0x7e60a8a55140> Operating System
microsoft windows_10_1903 - <built-in method update of dict object at 0x7e60bae48d80> Operating System
microsoft windows_10_1909 - <built-in method update of dict object at 0x7e61114e1c40> Operating System
microsoft windows_10_1909 - <built-in method update of dict object at 0x7e60a8a56a40> Operating System
microsoft windows_10_1909 - <built-in method update of dict object at 0x7e60a8a56600> Operating System
microsoft windows_7 - <built-in method update of dict object at 0x7e60a8a549c0> Operating System
microsoft windows_8.1 - <built-in method update of dict object at 0x7e60a8a55100> Operating System
microsoft windows_rt_8.1 - <built-in method update of dict object at 0x7e61114e1dc0> Operating System
microsoft windows_server_1903 - <built-in method update of dict object at 0x7e613410c200> Operating System
microsoft windows_server_1909 - <built-in method update of dict object at 0x7e60e8342f00> Operating System
microsoft windows_server_2008 - <built-in method update of dict object at 0x7e60eb2e3000> Operating System
microsoft windows_server_2008 r2 <built-in method update of dict object at 0x7e60e8341600> Operating System
microsoft windows_server_2008 r2 <built-in method update of dict object at 0x7e60a8a57f80> Operating System
microsoft windows_server_2012 - <built-in method update of dict object at 0x7e60bae4bd40> Operating System
microsoft windows_server_2012 r2 <built-in method update of dict object at 0x7e60a8a54ac0> Operating System
microsoft windows_server_2016 - <built-in method update of dict object at 0x7e60a8a54800> Operating System
microsoft windows_server_2019 - <built-in method update of dict object at 0x7e60a8a54a40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_1909:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
Yes cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Notification
Message here