Netskope Threat Labs

FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt

IPS-SWG

1 SID: 39260

First seen
January 2022
Last seen
October 2026

Detects a font exploiting CVE-2017-0192 and CVE-2016-3220, out-of-bounds access in the Windows kernel font driver that can allow privilege escalation. Rendering the crafted OpenType font corrupts kernel memory through the driver.