Netskope Threat Labs

FILE-OTHER Microsoft Windows fontdrvhost SetBlendDesignPositions out of bounds write attempt

IPS-CFW

1 SID: 53489

First seen
August 2022
Last seen
April 2023

Detects a font exploiting CVE-2020-0938, an out-of-bounds write in the Windows font driver host that can allow privilege escalation. The rule matches the crafted PostScript font values that public exploits use to corrupt the font process's memory.