CVE-2021-24093
published 2021-02-25CVE-2021-24093: Windows Graphics Component Remote Code Execution Vulnerability
PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
43.85%
98.6th percentile
Windows Graphics Component Remote Code Execution Vulnerability
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_2004 | — | — |
| msrc | windows_10_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-24093 is triggered via a specially crafted file served from a web-based attack scenario; defenders should monitor for users visiting attacker-controlled or compromised websites that serve malformed font files exploiting the Windows Graphics Component (DirectWrite). ↗
- →The vulnerability is triggered by malformed fonts processed by DirectWrite; OTS 'maxp' sanitization (commits b703837f4dda38239d and 1141c81c411b599e) was cherry-picked to reject such fonts as a mitigation — monitor for font parsing activity in DirectWrite on unpatched Windows systems. ↗
- →The attack vector requires user interaction: a user must click a link (typically delivered via email or Instant Messenger) and then open a specially crafted file. Phishing/spear-phishing delivery via email or IM should be monitored as the initial access vector. ↗
- →Additional technical details on the underlying bug are available in the Project Zero tracker (issue #2123); defenders can reference this for deeper signature development around the malformed font structure. ↗
- ·At time of Microsoft's patch release, the vulnerability had not been publicly disclosed or exploited in the wild; exploitation was rated 'Less Likely' for both latest and older software releases. ↗
- ·The Firefox/ESR mitigation (OTS maxp sanitization backport) protects against the vulnerability only on unpatched Windows versions; it is not a fix for the underlying Windows DirectWrite bug itself. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Graphics Component Remote Code Execution Vulnerability
vendor_msrc·2021-02-09·CVSS 8.8
CVE-2021-24093 [HIGH] Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.
Microsoft Graphics Component: Microsoft Graphics Component
Microsoft: Microsoft
Impact: Remote Cod
GHSA
GHSA-q4rp-937g-px7h: Windows Graphics Component Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-24093 [HIGH] GHSA-q4rp-937g-px7h: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Bugzilla
Cherry-pick OTS 'maxp' sanitization from upstream to ESR
bugzilla·2021-01-28·CVSS 8.8
[HIGH] Cherry-pick OTS 'maxp' sanitization from upstream to ESR
Cherry-pick OTS 'maxp' sanitization from upstream to ESR
OTS commits b703837f4dda38239d and 1141c81c411b599e are not present in ESR78; to protect against a known (though not yet public, afaik) issue in DirectWrite, we should cherry-pick these and apply to the version of OTS in the ESR tree.
(On trunk we have a more recent OTS already that includes this fix.)
Discussion:
Created attachment 9199826
Bug 1689395 - Backport some upstream OTS commits. r=jfkthame
---
Comment on attachment 9199826
Bug 1689395 - Backport some upstream OTS commits. r=jfkthame
### ESR Uplift Approval Request
* **If this is not a sec:{high,crit} bug, please state case for ESR consideration**: Protects against a DirectWrite vulnerability reported to us by Google
* **User impact if declined**: Users on unpatched
Checkpoint
March 1st – Threat Intelligence Report
blogs_checkpoint·2021-03-01
CVE-2021-21972 March 1st – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## March 1st – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The biochemical systems at an Oxford university research lab currently studying the Covid-19 pandemic has been breached . Clinical research was not affected by the incident. Breached systems include machines used to prepare biochemical samples, and hackers are currently attempting to sell their access to those machines.
Twitte
http://packetstormsecurity.com/files/161582/Microsoft-DirectWrite-fsg_ExecuteGlyph-Buffer-Overflow.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-24093http://packetstormsecurity.com/files/161582/Microsoft-DirectWrite-fsg_ExecuteGlyph-Buffer-Overflow.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-24093
2021-02-25
Published