CVE-2019-1245
MEDIUMWindows DirectWrite - Information Disclosure via Memory Exposure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-1245. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a memory corruption vulnerability in Microsoft DirectWrite (DWrite.dll) via a malformed OpenType font. The PoC triggers an invalid memory read in DWrite!SplicePixel, leading to a crash and potential information disclosure.
Description
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1251.
Exploits (1)
This exploit demonstrates a memory corruption vulnerability in Microsoft DirectWrite (DWrite.dll) via a malformed OpenType font. The PoC triggers an invalid memory read in DWrite!SplicePixel, leading to a crash and potential information disclosure.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N