« Volver al listado

CVE-2017-20190

Estado: AplazadaSin puntuar—

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-20190",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2017-20190",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-15T16:50:02.920361Z"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*"
          ],
          "vendor": "microsoft",
          "product": "windows",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "versionType": "custom",
              "lessThanOrEqual": "11"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-27T00:15:07.580",
  "references": [
    {
      "url": "https://aka.ms/windowsbugbar",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://en.wikipedia.org/wiki/Zalgo_text",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://talk.dynalist.io/t/dynalist-is-vulnerable-to-zalgo/1234",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://aka.ms/windowsbugbar",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://en.wikipedia.org/wiki/Zalgo_text",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://talk.dynalist.io/t/dynalist-is-vulnerable-to-zalgo/1234",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-176"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a \"Zalgo text\" attack. NOTE: third parties dispute whether the computational cost of interpreting Unicode data should be considered a vulnerability."
    },
    {
      "lang": "es",
      "value": "Algunas tecnologías de Microsoft utilizadas en Windows 8 a 11 permiten una degradación temporal del rendimiento del lado del cliente durante el procesamiento de múltiples caracteres combinados Unicode, también conocido como ataque de \"texto Zalgo\". NOTA: los terceros cuestionan si el costo computacional de interpretar los datos Unicode debe considerarse una vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T01:15:22.267",
  "sourceIdentifier": "cve@mitre.org"
}