Vulnerability Description
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.
Related Weaknesses (CWE)
References
- https://aka.ms/windowsbugbar
- https://en.wikipedia.org/wiki/Zalgo_text
- https://talk.dynalist.io/t/dynalist-is-vulnerable-to-zalgo/1234
- https://aka.ms/windowsbugbar
- https://en.wikipedia.org/wiki/Zalgo_text
- https://talk.dynalist.io/t/dynalist-is-vulnerable-to-zalgo/1234
FAQ
What is CVE-2017-20190?
CVE-2017-20190 is a documented vulnerability. Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack....
How severe is CVE-2017-20190?
CVSS scoring is not yet available for CVE-2017-20190. Check NVD for updates.
Is there a patch for CVE-2017-20190?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.