Impact
A heap‑based buffer overflow in the Windows Imaging Component allows an unauthorized attacker with local access to execute arbitrary code. The flaw is a classic memory corruption bug (CWE‑122) that can lead to full compromise of the host, affecting confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including Server Core editions. Both 32‑bit and 64‑bit builds are implicated as listed in the CPE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local execution risk, while the EPSS score of less than 1 % shows a very low probability of pre‑released exploitation. The vulnerability is not currently listed in the CISA KEV catalog, and its exploitation requires a user‑level presence on the affected system. Without a patch, an attacker could gain full control over any vulnerable machine.
OpenCVE Enrichment