-
CVE-2017-20190
- EPSS 0.1%
- Published 27.03.2024 00:15:07
- Last modified 21.11.2024 03:22:50
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendormicrosoft
≫
Product
windows
Default Statusunknown
Version <=
11
Version
8
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.276 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|
CWE-176 Improper Handling of Unicode Encoding
The product does not properly handle when an input contains Unicode encoding.