BIOC Informational

Unusual process spawned by fontdrvhost.exe

A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Exploitation for Client Execution (T1203)
Indicator:

Process action type = execution AND target process name != werfault.exe AND winlogon.exe AND wininit.exe AND csrss.exe AND fontdrvhost.exe Process initiated by = fontdrvhost.exe

Preventable: yes