Microsoft announced a new “zero day exploit”, which was discovered in all current versions of OS: Windows 7, 8.1 and Windows 10. The gap for library Adobe Type Managerused to display some fonts.
As it turned out, the library does not properly handle a specially crafted master font Adobe Type 1 Postscript fonts, allowing you to remotely execute code on the system. This vulnerability can be used in several ways. For example, you can convince a user to open a specially crafted document or to run them in preview mode in Explorer.
While in Redmond, said he was already working on a fix, although the timing of its release is not reported. Meanwhile, there are three options for a temporary workaround:
  • To disable the preview
  • To disable the WebClient service
  • Rename the file atmfd.dll.
