Executive brief
Graphic Fonts contains a heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code remotely over a network. An organization using this font rendering component in production systems could face unauthorized code execution, leading to data compromise, service disruption, or complete system takeover.
Technical details
A heap-based buffer overflow exists in Graphic Fonts, a component responsible for rendering and processing font files. The vulnerability can be triggered remotely over a network without requiring authentication or user interaction. An attacker can craft a malicious font file or network input that overflows the heap buffer, overwriting adjacent memory and achieving arbitrary code execution with the privileges of the affected application. Patches are expected from the vendor; refer to Microsoft Security Response Center for available updates.
Affected products
- Microsoft Graphic Fonts
Timeline
- 2026-09-08: disclosed