{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-20001","assignerOrgId":"b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b","state":"PUBLISHED","assignerShortName":"talos","dateReserved":"2025-03-17T17:07:47.093Z","datePublished":"2025-06-02T14:54:11.514Z","dateUpdated":"2025-06-02T17:03:57.718Z"},"containers":{"cna":{"affected":[{"vendor":"High-Logic","product":"FontCreator","versions":[{"version":"15.0.0.3015","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-125: Out-of-bounds Read","type":"CWE","cweId":"CWE-125"}]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"providerMetadata":{"orgId":"b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b","shortName":"talos","dateUpdated":"2025-06-02T14:54:11.514Z"},"references":[{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2025-2157","name":"https://talosintelligence.com/vulnerability_reports/TALOS-2025-2157"}],"credits":[{"lang":"en","value":"Discovered by KPC of Cisco Talos."}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-06-02T15:15:20.458187Z","id":"CVE-2025-20001","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-02T15:17:13.988Z"}},{"title":"CVE Program Container","references":[{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2157"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-06-02T17:03:57.718Z"}}]}}