Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-03-27 00:15
Updated : 2024-11-21 03:22
NVD link : CVE-2017-20190
Mitre link : CVE-2017-20190
CVE.ORG link : CVE-2017-20190
JSON object : View
Products Affected
No product.
CWE
CWE-176
Improper Handling of Unicode Encoding