Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.
CVSS
No CVSS.
References
Configurations
No configuration.
History
08 Aug 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-176 |
27 Mar 2024, 12:29
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 Mar 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-27 00:15
Updated : 2024-08-12 13:38
NVD link : CVE-2017-20190
Mitre link : CVE-2017-20190
CVE.ORG link : CVE-2017-20190
JSON object : View
Products Affected
No product.
CWE
CWE-176
Improper Handling of Unicode Encoding