Stats
- First seen
- August 2022
- Last seen
- April 2023
Description
Detects a font exploiting CVE-2020-0938, an out-of-bounds write in the Windows font driver host that can allow privilege escalation. The rule matches the crafted PostScript font values that public exploits use to corrupt the font process's memory.