{"id":"GHSA-c55g-rp4x-fx84","summary":"Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds","details":"### Impact\nThe spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.\n\nThis impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.\n\n\u003e Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.\n\n### Patches\nThis bug has been fixed in the May 7, 2026 release. Alternatively, users can update their copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791).\n\n### Workarounds\nThis does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.","modified":"2026-05-18T15:49:39.538575Z","published":"2026-05-18T15:38:15Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-18T15:38:15Z","nvd_published_at":null,"cwe_ids":["CWE-190"]},"references":[{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/security/advisories/GHSA-c55g-rp4x-fx84"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791"},{"type":"PACKAGE","url":"https://github.com/microsoft/DirectXTK"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/releases/tag/may2026"}],"affected":[{"package":{"name":"directxtk_desktop_win10","ecosystem":"NuGet","purl":"pkg:nuget/directxtk_desktop_win10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.5.8.1"}]}],"versions":["2020.11.12.1","2020.2.24.4","2020.5.10.1","2020.6.2.1","2020.7.2.1","2020.8.15.1","2020.9.30.1","2021.1.10.1","2021.10.1.1","2021.10.15.1","2021.10.19.1","2021.11.8.1","2021.4.7.2","2021.6.10.1","2021.8.2.1","2022.10.18.2","2022.12.16.1","2022.3.1.1","2022.3.24.2","2022.5.10.4","2022.7.30.1","2023.10.31.1","2023.2.7.1","2023.3.30.1","2023.4.28.1","2023.9.6.1","2024.1.1.1","2024.10.29.1","2024.2.22.1","2024.6.5.1","2024.9.5.1","2025.10.28.2","2025.3.21.2","2025.7.10.1","2026.4.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c 2026.4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-c55g-rp4x-fx84/GHSA-c55g-rp4x-fx84.json"}},{"package":{"name":"directxtk_uwp","ecosystem":"NuGet","purl":"pkg:nuget/directxtk_uwp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.5.8.1"}]}],"versions":["2015.10.30.1","2015.11.30.1","2015.7.29.1","2016.10.6.1","2016.12.5.1","2016.2.23.1","2016.4.26.1","2016.6.30.1","2016.7.18.1","2016.8.4.1","2016.9.1.1","2016.9.15.1","2017.12.13.1","2017.2.10.1","2017.4.24.1","2017.6.21.1","2017.9.22.1","2018.10.26.1","2018.10.31.1","2018.11.20.1","2018.4.23.1","2018.5.14.1","2018.6.1.2","2018.7.3.1","2018.8.18.2","2019.10.17.1","2019.12.17.1","2019.2.7.1","2019.4.26.1","2019.5.31.1","2019.8.23.1","2020.11.12.1","2020.2.24.4","2020.5.10.1","2020.6.2.1","2020.7.2.1","2020.8.15.1","2020.9.30.1","2021.1.10.1","2021.10.1.1","2021.10.15.1","2021.10.19.1","2021.11.8.1","2021.4.7.2","2021.6.10.1","2021.8.2.1","2022.10.18.2","2022.12.16.1","2022.3.1.1","2022.3.24.2","2022.5.10.4","2022.7.30.1","2023.10.31.1","2023.2.7.1","2023.3.30.1","2023.4.28.1","2023.9.6.1","2024.1.1.1","2024.10.29.1","2024.2.22.1","2024.6.5.1","2024.9.5.1","2025.10.28.2","2025.3.21.2","2025.7.10.1","2026.4.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c 2026.4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-c55g-rp4x-fx84/GHSA-c55g-rp4x-fx84.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}