CVE-2019-1128
HIGHWindows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-1128. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a heap buffer overflow in AFDKO's readCharset() function due to insufficient bounds checking, leading to memory corruption. It targets Adobe Font Development Kit for OpenType (AFDKO) and can be triggered via Microsoft Edge when printing a specially crafted OpenType variable font.
Description
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127.
Exploits (1)
The exploit demonstrates a heap buffer overflow in AFDKO's readCharset() function due to insufficient bounds checking, leading to memory corruption. It targets Adobe Font Development Kit for OpenType (AFDKO) and can be triggered via Microsoft Edge when printing a specially crafted OpenType variable font.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H