vendor:
Font Subsetting DLL (fontsub.dll)
by:
Anonymous
7.5
CVSS
HIGH
Access Violation
119
CWE
Product Name: Font Subsetting DLL (fontsub.dll)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Microsoft Font Subsetting DLL (fontsub.dll) Vulnerability
We have encountered the following crash in fontsub!FixSbitSubTableFormat1: We have developed a testing harness which invokes a pseudo-random sequence of API calls with a chosen font file passed as input. This report describes a crash triggered by a malformed font file in the fontsub.dll code through our harness.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all font files are properly validated before being used in any application.