CVE-2025-20001: High-Logic Fontcreator

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.

Affected products

Published 2025-06-02. Last modified 2026-06-17.