Impact
A heap‑based buffer overflow in the Windows GDI+ graphics library enables an attacker to execute arbitrary code without user interaction. The trusted input supplied over a network, giving the attacker control of application or system code at the privileges of the affected process. The primary consequence is loss of confidentiality, integrity, and availability for the compromised system.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. The vulnerability is present in the core GDI+ component across these operating system versions.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, and the EPSS score of less than 1% suggests a low probability of current exploitation in the wild, though the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based exploitation that requires the attacker to supply crafted graphics data to a vulnerable GDI+ consumer. No authentication is required, so any remote host can potentially exercise the flaw.
OpenCVE Enrichment