BIOC
Informational
✕
Unusual process spawned by fontdrvhost.exe
A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Exploitation for Client Execution (T1203)
Indicator:
Process action type = execution AND target process name != werfault.exe AND winlogon.exe AND wininit.exe AND csrss.exe AND fontdrvhost.exe Process initiated by = fontdrvhost.exe
Preventable: yes