CVE-2017-20190 Information

Description

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters aka a \Zalgo text\ attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.

Reference

https://talk.dynalist.io/t/dynalist-is-vulnerable-to-zalgo/1234 https://en.wikipedia.org/wiki/Zalgo_text https://aka.ms/windowsbugbar

Share on: