BIOC Informational

Fontdrvhost.exe makes network connections

A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation.

Module:
Platform Analytics
Agent event type:
Network
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Exploitation for Client Execution (T1203)
Indicator:

Network action type = incoming , outgoing , failed Process initiated by = fontdrvhost.exe

Preventable: yes