Executive brief
Windows Text Shaping is a system component that processes and renders text in Windows. An attacker with authorized local access could read data from memory that should not be accessible, potentially exposing sensitive information stored in the system's memory.
Technical details
The vulnerability is an out-of-bounds read in the Windows Text Shaping component, a system library responsible for text layout and rendering. The flaw allows an authorized local attacker to read memory locations beyond the intended bounds of a data structure, potentially disclosing sensitive information. The attack requires local access to the system but not elevated privileges. An attacker could leverage this to extract confidential data from process memory. A fix is expected to be available through Windows security updates.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed