news.volyx.in

Windows code-execution zeroday is under active exploit, Microsoft warns (arstechnica.com)

490 points by vo2maxer · 2390 days ago · 173 comments on HN

Article summary

A Windows code-execution zeroday exploit is under active attack, according to Microsoft. The vulnerability lies in the Windows Adobe Type Manager Library ATMFD.DLL and can be exploited by embedding Type 1 fonts into documents. Disabling the Windows WebClient service can block the most likely remote attack vector. Local, authenticated users can also run malicious programs to exploit the vulnerability.

Main themes

  • Windows zeroday exploit
  • ATMFD.DLL vulnerability
  • AppContainer sandbox
  • Windows graphics stack
  • Proprietary software security risks
  • Font rendering and Postscript fonts

What commenters say

  • The vulnerability is not as severe for Windows 10 users due to the AppContainer sandbox, which limits the privileges and capabilities of the exploited code.
  • The ATMFD.DLL component is a Microsoft component that was heavily forked from purchased Adobe code, and its presence in Windows is necessary for displaying Postscript Type 1 fonts.
  • Some argue that having a proprietary component like ATMFD.DLL in the core system is an increased security risk, while others point out that Adobe has not been involved with the code for decades.
  • Removing or disabling the ATMFD.DLL component is not a viable solution due to its essential role in rendering Postscript fonts, particularly in PDF files.
  • The Windows graphics stack is a complex and vulnerable area, with a history of exploits and vulnerabilities.
  • There are differing opinions on the severity of the vulnerability and the effectiveness of the AppContainer sandbox in mitigating it.
  • The use of proprietary software components in core system functions can be a security risk, but in this case, the component has been maintained by Microsoft for years.