Executive brief
Graphic Fonts contains a heap-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code over the network without authentication. Successful exploitation could lead to complete system compromise, including unauthorized access to sensitive data and business systems.
Technical details
The vulnerability is a heap-based buffer overflow in Graphic Fonts that can be triggered remotely without authentication. The root cause involves improper bounds checking when processing font data, allowing an attacker to overflow heap memory and overwrite critical data structures. An attacker can send a specially crafted network packet to trigger the overflow and execute arbitrary code with the privileges of the affected process. No authentication or user interaction is required for exploitation via the network attack vector.
Affected products
- Graphic Fonts
Timeline
- 2026-09-08: disclosed