PT-2024-10599 · Microsoft · Windows 11+3
Dos
·
Published
2024-03-26
·
Updated
2024-08-12
·
CVE-2017-20190
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 8 through 11
Description
The issue concerns a temporary client-side performance degradation that occurs when processing multiple Unicode combining characters, also known as a "Zalgo text" attack. This affects the processing of Unicode data. There is a dispute among third parties regarding whether the computational cost of interpreting Unicode data should be considered a vulnerability.
Recommendations
For Microsoft Windows versions 8 through 11, consider restricting the processing of multiple Unicode combining characters to minimize the risk of temporary performance degradation. As a temporary workaround, avoid using sequences of Unicode combining characters in client-side applications until a more robust solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows 10
Windows 11
Windows 8
Windows 9