PT-2012-2356 · Microsoft · Directwrite+1
Khaled M. Salameh
·
Published
2012-03-13
·
Updated
2023-12-07
·
CVE-2012-0156
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
A denial of service issue exists due to improper rendering of Unicode characters by DirectWrite. This allows remote attackers to cause an application hang via an instant message or a web site. The estimated number of potentially affected devices is not specified.
Recommendations
For Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1, update to a version that includes the fix for the DirectWrite Application Denial of Service issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directwrite
Windows