
Microsoft Active Directory (AD) administrators can mitigate the impact of a newly disclosed zero-day vulnerability that allows remote code execution in the Windows Adobe Type Manager Library in large AD environments. Mitigation can be done using group policy (GPO).
Microsoft said on March 23 that it had detected some targeted attacks on devices running Windows 7 , attempting to exploit two unpatched vulnerabilities (one new and one older) in the Adobe Type Manager Library.
The vulnerabilities affect devices running desktop and server versions of Windows, including Windows 10, Windows 8.1, Windows 7, and multiple versions of Windows Server.
To exploit security issues , attackers trick victims into opening malicious documents or simply viewing them through the Windows Preview pane.
Microsoft has already provided some solutions to mitigate the risks posed by attacks using these vulnerabilities. Some of these solutions include disabling the Preview and Details panes in Windows Explorer , disabling the WebClient service , and renaming the vulnerable library (ATMFD.DLL).
However, Microsoft solutions are not easy to implement to mitigate attacks on an enterprise.
According to Sylvain Cortes, you can mitigate the problem with the help of group policy (Group Policy Object-GPO).
Using GPOs to mitigate risk in businesses
First of all, open the GPMC console and create a new GPO by right-clicking on the “Group Policy Objects”.
Next, go to: User Configuration>Policies>Administrative Templates>Windows Components>File Explorer and enable the two GPO options shown in the image below. This will disable the preview locally and across the entire network.

“Close the GPO and link this GPO to all user accounts in your organization”, added Sylvain.
Then, create a new GPO through GPMC and disable the WebClient service from Computer Configuration>Policies>Windows Settings>Security Settings>System Services.
This GPO must also be linked to all accounts in organization to disable WebClient everywhere.

Both GPOs should be rolled back when Microsoft releases an update to fix the font parsing zero-day vulnerabilities.
Microsoft said it is working on fixing the zero-day vulnerability and hinted that this will be done with the release of the new Patch Tuesday (on April 14).
