Impact
Heap‑based buffer overflow in the Graphic Fonts component allows an attacker to execute arbitrary code in a system that processes font data. The flaw arises from improper bounds checking during memory allocation. Based on the description, it is inferred that the attacker can trigger the overflow by sending crafted data over a network, enabling remote exploitation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012 to 2025, including Server Core variants. All listed architectures (x86, x64, arm64) are affected.
Risk and Exploitability
Severity is high with a CVSS score of 8.8. EPSS data is unavailable, so exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV, indicating no confirmed exploitation reports. The description indicates the attack vector is network‑based, and exploitation would grant execution of code under the context of the process that loads fonts, potentially allowing unrestricted control over the affected machine.
OpenCVE Enrichment