Impact
The vulnerability is a heap‑based buffer overflow in the Windows GDI+ component that can be triggered by an unauthenticated attacker who forces the system to process malicious graphics data. The overflow can lead to execution of arbitrary code in the context of the user who owns the process, resulting in local code execution. The flaw is classified as CWE‑122, a classic memory corruption issue.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Windows Server editions 2012, 2016, 2019, 2022 and 2025, including Server Core installations where applicable.
Risk and Exploitability
The CVSS base score of 8.4 indicates a high severity local exploitation surface, while the EPSS score of less than 1% points to a low probability of widespread exploitation at present. The flaw is not current in the CISA KEV catalog, suggesting it has not been widely observed in the wild. The likely attack vector requires an attacker to cause the target machine to load crafted graphics or image data locally, such as by opening a malicious file or running an application that renders vector graphics. If successfully exploited, the attacker could run arbitrary code in the context of the user who owns the process.
OpenCVE Enrichment