vendor:
Windows Uniscribe user-mode library
by:
Google Project Zero
N/A
CVSS
MEDIUM
Memory Corruption
125
CWE
Product Name: Windows Uniscribe user-mode library
Affected Version From: Windows Uniscribe user-mode library
Affected Version To: Windows Uniscribe user-mode library
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
Crash in Windows Uniscribe user-mode library
A crash occurs in the Windows Uniscribe user-mode library, specifically in the USP10!otlReverseChainingLookup::apply function. The crash is triggered when attempting to display text using a corrupted TTF font file.
Mitigation:
To mitigate this vulnerability, users should avoid using or opening corrupted TTF font files.