vendor:
DirectWrite
by:
7.5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: DirectWrite
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Microsoft DirectWrite Memory Corruption
The exploit is caused by an invalid memory read in DWrite!sfac_GetSbitBitmap while rasterizing the glyphs of a slightly malformed TrueType font. This vulnerability can be triggered by embedding a proof-of-concept font in a web page.
Mitigation:
Apply the latest security updates from Microsoft. Avoid opening untrusted font files or visiting malicious websites.