This makes exploits like this possible: https://sensepost.com/blog/2017/abusing-gdi-objects-for-ring...
I don’t know of any specific blogs/resources. I used to work on Excel’s render code so had a bit of an inside view.
The Vista experience shows you it was and still is necessary for perf.
Moving things into the kernel is one heck of a sledgehammer solution to DLL Hell, at least.
(Windows 10 has slowly moved a lot of the graphics stack back out of kernel space. It appears to be moving the right direction, just very slowly.)
There is:
https://portal.msrc.microsoft.com/en-US/security-guidance/ad...
Microsoft documents, as a possibility, how to "Rename ATMFD.DLL" and describes the impact.
> Rename ATMFD.DLL, or alternatively, disable the file from the registry
Caveat:
> Renaming ATMFD.DLL, the last recommended stopgap, will cause display problems for applications that rely on embedded fonts and could cause some apps to stop working if they use OpenType fonts.
Also from TFA:
> Monday’s advisory provides detailed instructions for both turning on and turning off all three workarounds.
(If you're reading lots of LaTeX-generated papers, then yes, you're probably seeing PostScript fonts.)