Impact
The vulnerability is a heap‑based buffer overflow in Windows Text Shaping that permits an unauthenticated attacker to execute arbitrary code when processing text over a network. The flaw originates from insufficient bounds checking, which is identified as CWE‑122. With a CVSS score of 8.1, the flaw represents a high‑severity risk that could compromise confidentiality, integrity, and availability of the affected systems.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, across both marketing and server core installations. No specific build or architectural constraints are listed beyond the general product family.
Risk and Exploitability
The CVSS indicates a significant severity, but the EPSS score is not available, and the vulnerability has not been recorded in CISA’s KEV catalog. The likely attack vector is through network traffic that contains maliciously crafted text input, requiring no prior authentication. An attacker could trigger the overflow to gain code execution privilege, potentially leading to full system compromise. Because the flaw is network‑exposed, prompt patching and monitoring are essential.
OpenCVE Enrichment