Windows DirectWrite vulnerability could allow denial of service
Report ID: MS201203003
Date Published: 14 March 2012
Compromise Type: denial-of-service
Compromise From: remote
Windows Server 2008
Windows Server 2008 R2
A vulnerability found in Windows DirectWrite could be exploited into causing a target application to stop responding.
Microsoft has issued a security update to resolve a denial of service vulnerability found in DirectWrite, which is a text rendering API. The vulnerability was caused by incorrect rendering of a sequence of Unicode characters. Upon successful exploit, an attacker could cause a target application to stop responding.
This vulnerability has been resolved in the update issued by Microsoft, which introduces changes in the way that DirectWrite renders Unicode characters. Users are recommended to install this update to protect their system from potential exploit attempt.
Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-019)