vendor:
Windows
by:
Project Zero
5.5
CVSS
MEDIUM
Memory Corruption
125
CWE
Product Name: Windows
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Windows Kernel Crash in win32k!itrp_GetCVTEntryFast
The win32k!itrp_GetCVTEntryFast function in Windows kernel crashes when processing corrupted TTF font files, leading to a PAGE_FAULT_IN_NONPAGED_AREA error. This can be triggered by a read or write operation on the fb000078 memory address. The bug occurs in the win32k.sys module and affects the csrss.exe process. The crash is caused by an invalid system memory reference.
Mitigation:
Apply the latest updates and patches from Microsoft to address this vulnerability.