7.8

CVE-2020-1355

A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory., aka 'Windows Font Driver Host Remote Code Execution Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 10 Version 2004
Microsoft ≫ Windows Server 2016 Version 1903
Microsoft ≫ Windows Server 2016 Version 1909
Microsoft ≫ Windows Server 2016 Version 2004
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.95% 0.891
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1355
Patch
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-875/
Third Party Advisory
VDB Entry