EIP-2026-115636

PRE-CVE

Microsoft DirectWrite / AFDKO - Stack-Based Buffer Overflow in do_set_weight_vector_cube for Large nAxes

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115636. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in AFDKO's `do_set_weight_vector_cube()` function, triggered by a maliciously crafted OpenType font file with an excessive number of axes (nAxes > 9). The vulnerability arises due to insufficient bounds checking, leading to overflows in local buffers and heap structures.

Description

Microsoft DirectWrite / AFDKO - Stack-Based Buffer Overflow in do_set_weight_vector_cube for Large nAxes

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdoswindows
https://www.exploit-db.com/exploits/47089

This exploit demonstrates a stack-based buffer overflow in AFDKO's `do_set_weight_vector_cube()` function, triggered by a maliciously crafted OpenType font file with an excessive number of axes (nAxes > 9). The vulnerability arises due to insufficient bounds checking, leading to overflows in local buffers and heap structures.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: AFDKO (Adobe Font Development Kit for OpenType) and potentially Microsoft DirectWrite (if CFR_FLATTEN_CUBE flag is set)
No auth needed
Prerequisites: A vulnerable version of AFDKO or a system using the affected code path in DirectWrite · A maliciously crafted OpenType font file with an excessive number of axes
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026