A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1436 | patch vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-877/ | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2020/08/25/3 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2020/08/25/5 | third party advisory mailing list |