Microsoft Reveals New Windows Vulnerability That Allows Hackers to Remotely Run Malware on PCs

Microsoft has said that it is working on a fix. In the meantime, the company suggested few temporary measures.

Advertisement
By Darab Mansoor Ali | Updated: 24 March 2020 16:50 IST
Highlights
  • Microsoft issued an advisory for the new Windows vulnerability
  • Microsoft has suggested temporary measures till the next security update
  • The vulnerability involves Adobe’s Type Manager Library

Hackers can remotely run malware if they successfully exploit the vulnerability

Microsoft has found a previously undisclosed vulnerability its Windows operating system for PCs. The vulnerability can be found in all supported versions of Windows, including Windows 10. Microsoft announced the vulnerability in an advisory, which said that it is being exploited in the form of limited targeted attacks. It means that if a hacker successfully pulls off an attack on a computer, they could remotely run a malware on the victim's device. The vulnerability involves Adobe's Type Manager Library that is used to render fonts in Windows.

In its advisory, Microsoft said that the limited targeted attacks that could leverage unpatched vulnerabilities in the Adobe Type Manager Library, through which an attacker can leverage fonts. The company further provided guidelines to users in order to minimize the risk until a security update is released. Using this vulnerability, an attacker can trick a user into opening a specially crafted document or view it in the Windows Preview pane, through which they can remotely run a malware or a malicious code on a victim's device.

Advertisement

"There are multiple ways an attacker could exploit the vulnerability, such as convincing a user to open a specially crafted document or viewing it in the Windows Preview pane," the Microsoft advisory said. The vulnerability has been rated 'critical,' Microsoft's highest rating.

Now, although Microsoft has said that it is working on a fix, the company notes that updates to address security vulnerabilities are usually released as part of Update Tuesdays, which is the second Tuesday of every month. In the meantime, it has listed out instructions for a few temporary workarounds in the advisory, like disabling Preview Pane and Details Pane in Windows Explorer. Microsoft has also listed out the Windows versions that are affected by this vulnerability.

Advertisement

In its statements to The Verge and TechCrunch, Microsoft said that the security patch for this vulnerability will land on the next Update Tuesday, slated for April 14.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G37, Moto G37 Power Launched in India With These Features
  2. Here Are the Best Smartphones in India Under Rs. 30,000
  3. Motorola Edge 70 Pro+ Confirmed to Launch in India Soon in These Shades
  4. This Xiaomi 17 Series Could Launch in India Soon
  5. Lava Shark 2 5G Confirmed to Launch in India This Month With 120Hz Display
  6. Take-Two Reaffirms GTA 6 Release Date, Says Game Was Delayed by 18 Months
  7. How to Claim PF Online Without Employer Approval Under New EPFO Rules
  8. Meta Planning to Cut 10 Percent of Workforce as Part of AI Overhaul
  9. Android 17 Leak Reveals Google's Noto 3D Emojis
  10. Google Reportedly Aware of This Major Gmail App Issue Affecting Many Users
  1. Samsung Galaxy S26 Series Sales Outpace Galaxy S25 Lineup in First Six Weeks: Counterpoint
  2. Meta Planning to Lay Off 10 Percent of Workforce as Part of AI Driven Restructuring
  3. Moto Buds 2 Launched in India With Up to 48 Hours Battery Life, Dual 11mm Dynamic Drivers: Price, Features
  4. Moto G37, Moto G37 Power Launched in India With Dimensity 6400 Chipset: Price, Specifications
  5. Xiaomi 17T India Launch Seemingly Confirmed a Week Ahead of Global Debut
  6. Amazon Alexa+ Can Now Create AI-Powered Podcast Episodes on Demand
  7. Take-Two CEO Strauss Zelnick Reaffirms GTA 6 Release Date, Says Game Was Delayed by 18 Months
  8. Google’s Upcoming Noto 3D Emojis for Android 17 Revealed in New Leak
  9. Google Is Aware of Gmail App Flickering Issue Affecting Various Android Tablet and Foldable Users, Report Claims
  10. Lava Shark 2 5G Confirmed to Launch in India This Month With 120Hz Display
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.