{"id":"GHSA-5r97-79vw-qvm4","summary":"Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds","details":"### Impact\nThe spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.\n\nThis impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.\n\n\u003e Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.\n\n### Patches\nThis bug has been fixed in the May 7, 2026 release. Alternatively, you can just update your copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494).\n\n### Workarounds\nThis does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.","modified":"2026-05-18T15:49:42.342845Z","published":"2026-05-18T15:38:59Z","database_specific":{"cwe_ids":["CWE-190"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-18T15:38:59Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/security/advisories/GHSA-5r97-79vw-qvm4"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494"},{"type":"PACKAGE","url":"https://github.com/microsoft/DirectXTK12"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/releases/tag/may2026"}],"affected":[{"package":{"name":"directxtk12_desktop_win10","ecosystem":"NuGet","purl":"pkg:nuget/directxtk12_desktop_win10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.5.8.1"}]}],"versions":["2025.10.28.1","2025.3.21.3","2025.7.10.1","2026.4.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c 2026.4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5r97-79vw-qvm4/GHSA-5r97-79vw-qvm4.json"}},{"package":{"name":"directxtk12_uwp","ecosystem":"NuGet","purl":"pkg:nuget/directxtk12_uwp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.5.8.1"}]}],"versions":["2016.10.6.1","2016.12.5.1","2016.6.30.1","2016.7.18.1","2016.8.4.1","2016.9.1.1","2016.9.15.1","2017.12.13.1","2017.2.10.1","2017.4.24.1","2017.6.21.1","2017.9.22.1","2018.10.26.1","2018.10.31.1","2018.11.20.1","2018.4.23.1","2018.5.14.1","2018.6.1.2","2018.7.3.1","2018.8.18.2","2018.9.13.1","2019.10.17.1","2019.12.17.1","2019.2.7.1","2019.4.26.1","2019.5.31.1","2019.8.23.1","2020.11.12.1","2020.2.24.1","2020.5.11.1","2020.6.15.1","2020.6.2.1","2020.7.2.1","2020.8.15.1","2020.9.30.1","2021.1.10.1","2021.10.1.1","2021.10.15.1","2021.10.19.1","2021.11.8.1","2021.4.7.2","2021.6.10.2","2021.8.2.1","2022.10.18.1","2022.12.18.1","2022.3.1.1","2022.3.24.1","2022.5.10.1","2022.7.30.1","2023.10.31.1","2023.2.7.1","2023.3.30.1","2023.4.28.1","2023.9.6.2","2024.1.1.1","2024.10.29.1","2024.2.22.1","2024.6.5.1","2024.9.5.1","2025.10.28.1","2025.3.21.3","2025.7.10.1","2026.4.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c 2026.4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5r97-79vw-qvm4/GHSA-5r97-79vw-qvm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}