Details Available on Patched Adobe, Windows Font Vulnerabilities

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
A Google Project Zero researcher has publicly disclosed details on a number of patched Adobe and Microsoft vulnerabilities, including one in the Adobe Type Manager Font Driver that could enable takeover of a number of systems supporting modern font engines.

Mateusz Jurczyk pointed the finger at how CharStrings are handled as the principal culprit, in particular the quality of its interpreter function in ATMFD.dll; CharStrings provide instructions for drawing the shape of each glyph at a particular point size, he said.
https://threatpost.com/details-available-on-patched-adobe-windows-font-vulnerabilities/113454
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top