ZeroHour

CVE-2026-69786

mass

Heap Buffer Overflow RCE in Windows Text Shaping

CVSS 3.1
8.1 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-69786 is a heap-based buffer overflow (CWE-122) in the Windows Text Shaping component of Microsoft Windows. An unauthenticated attacker can trigger the flaw remotely over a network to execute arbitrary code in the context of the affected Windows process. The CVSS vector indicates no user interaction is required, though high attack complexity suggests exploitation requires nontrivial conditions. All Windows installations that include the Text Shaping engine are potentially affected, but Microsoft has not enumerated specific affected versions in the provided data. As of now, there are no public proofs of concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.

What to do: Monitor Microsoft's security bulletin for the affected version ranges and apply the released patch promptly, prioritizing systems that expose network services capable of processing untrusted text or fonts. Until patched, limit exposure of such Windows hosts to untrusted network input where possible and verify patch applicability against your OS inventory once Microsoft lists exact versions.

Affected
Microsoft Windows Text Shaping component
Estimated exposure
mass≈1 billion+ Windows installations ship the in-box Text Shaping component, though the affected version subset is unknown — The vulnerable component ships with the Windows operating system, which Microsoft has stated runs on over a billion active devices, so reach is bounded only by the affected version range Microsoft publishes.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.