EIP-2026-115630
PRE-CVEMicrosoft DirectWrite / AFDKO - Heap-Based Buffer Overflow Due to Integer Overflow in readTTCDirectory
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-115630. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a heap-based buffer overflow in AFDKO's readTTCDirectory function due to an integer overflow when processing a malformed TTC font file. The PoC triggers the vulnerability by setting DirectoryCount to 0x40000001, leading to memory corruption during font parsing.
Description
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow Due to Integer Overflow in readTTCDirectory
Exploits (1)
The exploit demonstrates a heap-based buffer overflow in AFDKO's readTTCDirectory function due to an integer overflow when processing a malformed TTC font file. The PoC triggers the vulnerability by setting DirectoryCount to 0x40000001, leading to memory corruption during font parsing.