CVE-2017-20190: Microsoft Windows

EPSS: 0.3% chance of exploitation in the next 30 days.

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.

Affected products

  • Microsoft Windows: from 8, up to and including 11

Published 2024-03-27. Last modified 2026-06-17.