Microsoft Reveals New Windows Vulnerability That Allows Hackers to Remotely Run Malware on PCs

Microsoft has said that it is working on a fix. In the meantime, the company suggested few temporary measures.

Advertisement
By Darab Mansoor Ali | Updated: 24 March 2020 16:50 IST
Highlights
  • Microsoft issued an advisory for the new Windows vulnerability
  • Microsoft has suggested temporary measures till the next security update
  • The vulnerability involves Adobe’s Type Manager Library
Microsoft Reveals New Windows Vulnerability That Allows Hackers to Remotely Run Malware on PCs

Hackers can remotely run malware if they successfully exploit the vulnerability

Microsoft has found a previously undisclosed vulnerability its Windows operating system for PCs. The vulnerability can be found in all supported versions of Windows, including Windows 10. Microsoft announced the vulnerability in an advisory, which said that it is being exploited in the form of limited targeted attacks. It means that if a hacker successfully pulls off an attack on a computer, they could remotely run a malware on the victim's device. The vulnerability involves Adobe's Type Manager Library that is used to render fonts in Windows.

In its advisory, Microsoft said that the limited targeted attacks that could leverage unpatched vulnerabilities in the Adobe Type Manager Library, through which an attacker can leverage fonts. The company further provided guidelines to users in order to minimize the risk until a security update is released. Using this vulnerability, an attacker can trick a user into opening a specially crafted document or view it in the Windows Preview pane, through which they can remotely run a malware or a malicious code on a victim's device.

"There are multiple ways an attacker could exploit the vulnerability, such as convincing a user to open a specially crafted document or viewing it in the Windows Preview pane," the Microsoft advisory said. The vulnerability has been rated 'critical,' Microsoft's highest rating.

Now, although Microsoft has said that it is working on a fix, the company notes that updates to address security vulnerabilities are usually released as part of Update Tuesdays, which is the second Tuesday of every month. In the meantime, it has listed out instructions for a few temporary workarounds in the advisory, like disabling Preview Pane and Details Pane in Windows Explorer. Microsoft has also listed out the Windows versions that are affected by this vulnerability.

Advertisement

In its statements to The Verge and TechCrunch, Microsoft said that the security patch for this vulnerability will land on the next Update Tuesday, slated for April 14.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Bold N1, Lava Bold N1 Pro India Pricing, Specifications Teased
  2. Noise Buds F1 With Up to 50-Hour Playback Time Debuts at This Price Tag
  3. Vijay Sales Apple Days Sale Brings Discounts on These iPhone, Mac Models
  4. Infinix GT 30 Pro 5G India Launch Date, Colours, Key Features Confirmed
  5. Honor Pad 10 With Snapdragon 7 Gen 3 SoC, 10,100mAh Battery Launched
  6. Realme GT 7 Series: Launch Date, Expected Price in India and More
  7. Xiaomi Pad 7 Ultra With XRING 01 SoC and 12,000mAh Battery Launched
  1. Vivo X200 FE Reportedly Listed on BIS, IMDA Certification Websites Ahead of Anticipated Launch in India
  2. Oracle Said to Buy $40 Billion of Nvidia Chips for OpenAI's US Data Center
  3. Trump Threatens 25 Percent Tariffs on Apple If iPhones Not Made in US
  4. iPhone 16 Pro Max, iPhone 15, MacBook Air (M4) and More Get Discounts During Vijay Sales Apple Days Sale
  5. Anthropic CEO Dario Amodei Says AI Models Hallucinate Less Than Humans: Report
  6. UK Government Updates Crypto Reporting Guidelines, Mandates Collection of Crypto Transaction Data
  7. Acer Swift Neo WIth Intel Core Ultra 5, Up to 32GB RAM Launched in India: Price, Specifications
  8. Elden Ring Film Adaptation in the Works at A24 With Alex Garland Set to Direct
  9. Noise Buds F1 TWS Earbuds With IPX5 Rating, Up to 50-Hour Total Playback Time Launched in India
  10. News Media Alliance Issues Statement on Google’s AI Mode, Calls It ‘Definition of Theft’
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.