Skip to content
COOEY

EXPOSURES › CVE-2020-15999

CVE-2020-15999

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-15999 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain.

The vulnerability allowed remote code execution via malicious PNG images embedded in fonts, which was part of a known exploit chain targeting Windows and Android. DIB organizations must ensure their browsers are patched and monitor for supply-chain compromises in open-source libraries like FreeType. This is not a zero-day as it was part of an active exploit chain.

Shame score — The vulnerability was actively exploited in the wild as part of an exploit chain, indicating a failure to patch a known issue before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized