vendor:
Windows Uniscribe user-mode library
by:
Project Zero
9,8
CVSS
HIGH
Memory Read Access Vulnerability
119
CWE
Product Name: Windows Uniscribe user-mode library
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2018
Windows Uniscribe User-Mode Library Memory READ Access Vulnerability
Through fuzzing, a number of different crashes in the Windows Uniscribe user-mode library were discovered while trying to display text using a corrupted font file or calling documented Uniscribe API functions against such malformed fonts. These crashes manifest through invalid memory READ accesses, some of which occur at page boundaries, while other at seemingly valid yet non-mapped addresses.
Mitigation:
Update to the latest version of Windows Uniscribe user-mode library.