vendor:
Font Subsetting DLL
by:
Anonymous
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Font Subsetting DLL
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Microsoft Font Subsetting DLL (fontsub.dll) Crash
A buffer overflow vulnerability was discovered in the Microsoft Font Subsetting DLL (fontsub.dll) which is a default Windows helper library for subsetting TTF fonts. The vulnerability is triggered by a malformed font file in the fontsub.dll code through a testing harness which invokes a pseudo-random sequence of API calls with a chosen font file passed as input.
Mitigation:
Microsoft has released a patch to address this vulnerability.