PT-2020-2196 · Microsoft+1 · Windows+1

Published

2020-04-14

·

Updated

2025-10-29

·

CVE-2020-0938

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description A remote code execution issue exists in Microsoft Windows due to the improper handling of a specially-crafted multi-master font in the Adobe Type 1 PostScript format by the Windows Adobe Type Manager Library. This allows an attacker to execute code remotely. The vulnerability can be exploited through a specially-crafted document, potentially leading to the execution of arbitrary code and affecting the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2020-02100
CVE-2020-0938

Affected Products

Type Manager Library
Windows