Lucene search

K
attackerkbAttackerKBAKB:D673396D-06D8-4D50-B1AD-97679B53A487
HistoryApr 15, 2020 - 12:00 a.m.

CVE-2020-1020

2020-04-1500:00:00
attackerkb.com
28

EPSS

0.949

Percentile

99.3%

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font – Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka ‘Adobe Font Manager Library Remote Code Execution Vulnerability’. This CVE ID is unique from CVE-2020-0938.

Recent assessments:

gwillcox-r7 at November 22, 2020 2:27am UTC reported:

Reported as exploited in the wild as part of Google’s 2020 0day vulnerability spreadsheet they made available at <https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit#gid=1869060786&gt;. Original tweet announcing this spreadsheet with the 2020 findings can be found at <https://twitter.com/maddiestone/status/1329837665378725888&gt;

This is pretty similar to CVE-2020-1020 and its possible they were used together in a single attack, although for now this is just my theory and without full evidence this should be taken with a healthy few grains of salt.

Assessed Attacker Value: 0
Assessed Attacker Value: 0Assessed Attacker Value: 0