Impact
A heap‑based buffer overflow exists in Graphic Fonts that allows an unauthorized attacker to execute arbitrary code over a network. Because the flaw is located in the font rendering engine, the code runs with the privileges of the process loading the font, potentially enabling full compromise of the affected system.
Affected Systems
The vulnerability affects Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, Windows Server 2012 (full and core), Windows Server 2012 R2 (full and core), Windows Server 2016, Windows Server 2019 (full and core), Windows Server 2022, and Windows Server 2025 (full and core).
Risk and Exploitability
The flaw carries a CVSS score of 8.8 and currently has no EPSS or KEV listing. Attackers can exploit the heap overflow by delivering a malicious font file over a network connection to a vulnerable Windows system. Successful exploitation results in arbitrary code execution with the privileges of the font rendering process, representing a high‑severity threat that can compromise confidentiality, integrity, and availability.
OpenCVE Enrichment