Stats
- First seen
- January 2023
- Last seen
- February 2026
Description
Detects a font exploiting CVE-2020-1020, a stack overflow in the Windows Adobe Type 1 font driver that can allow privilege escalation. The rule matches the crafted font metrics that public exploits use to corrupt kernel memory.