Windows Kernel NtGdiGetTextExtentExW Out-Of-Bounds Memory Read

The included proof of concept crashes Windows 7 with special pool enabled on win32k.sys. The crash is due to accessing memory past the end of a buffer.

Leave a Reply