Junglewise Threat Intelligence

Microsoft DirectXTK12 integer overflow in SpriteFont reader

Severity: medium · CVSS 6.9 · Published 2026-05-18

Vendors: NuGet, Microsoft.

Executive brief

A vulnerability exists in the Microsoft DirectX Tool Kit for DirectX 12, a library used by developers to handle graphics and game assets. When an application built for 32-bit systems (x86 or ARM) processes a specially crafted font file, it can trigger a memory error. This could potentially allow an attacker to execute unauthorized code or cause the application to crash if it processes untrusted files from the internet or users.

Technical details

An integer overflow vulnerability (CWE-190) exists in the SpriteFont class file loading constructor within the Microsoft DirectX Tool Kit (DirectXTK12). The vulnerability is triggered when the spritefont reader performs a 32-bit multiplication that overflows, which can occur when processing malformed or untrusted .spritefont data files. This issue specifically affects 32-bit architectures (x86 and ARM); 64-bit builds (x64 and ARM64) are not impacted. Successful exploitation could theoretically lead to remote code execution (RCE) in the context of the application. The issue has been patched in the May 2026 release (version 2026.5.8.1).

Affected products

  • Microsoft DirectXTK12 (DirectX Tool Kit) < 2026.4.1.1

Timeline

  • 2026-05-07: patched: Fix included in the May 2026 release
  • 2026-05-11: disclosed: Initial disclosure by author
  • 2026-05-18: advisory: GitHub Advisory published

References

Related threats