BIOC
Informational
✕
Fontdrvhost.exe makes network connections
A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation.
- Module:
- Platform Analytics
- Agent event type:
- Network
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Exploitation for Client Execution (T1203)
Indicator:
Network action type = incoming , outgoing , failed Process initiated by = fontdrvhost.exe
Preventable: yes