vendor:
Windows 10
by:
Gareth Evans
7.8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Windows 10
Affected Version From: Windows 10 Version 1709
Affected Version To: Windows 10 Version 2004
Patch Exists: YES
Related CWE: CVE-2020-17092
CPE: 2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*
Other Scripts:
N/A
Platforms Tested: Windows
2020
Buffer Overflow in Microsoft Font Subsetting DLL
A buffer overflow vulnerability exists in the Microsoft Font Subsetting DLL (fontsub.dll) when processing a malformed font file. This vulnerability can be triggered by a pseudo-random sequence of API calls with a chosen font file passed as input. The vulnerable code is located in the fontsub!ReadAllocFormat12CharGlyphMapList function, where a mov instruction is used to write a value to a memory address without validating the size of the destination buffer. An attacker can exploit this vulnerability by supplying a specially crafted font file, resulting in a buffer overflow and potentially allowing arbitrary code execution.
Mitigation:
Microsoft has released a security update to address this vulnerability. Users and administrators are advised to apply the necessary updates to affected systems.