Impact
A heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute arbitrary code locally. The vulnerability can be triggered during normal use of G and availability of any user or process that creates or processes image data.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local code execution, while the EPSS score of less than 1% shows that the exploitation probability is currently very low. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is an attacker with local access who can trigger GDI+ rendering, such as by providing malicious image data to a susceptible application or by running arbitrary exploit code on the affected system.
OpenCVE Enrichment