Impact
The vulnerability is an out‑of‑bounds read in the Microsoft Graphics Component. Because of a flaw in how the component validates or processes graphical data, an attacker can trigger code execution when a crafted image or other graphic asset is processed. This weakness, classified as CWE‑125, permits the attacker to run arbitrary code on the local system, undermining confidentiality, integrity, and availability. With a CVSS base score of 7.8, the flaw is considered high severity. The description does not specify the attacker context; it is inferred that local execution under user privileges is the likely scenario.
Affected Systems
Affected systems include Microsoft Windows 10 version 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Windows Server releases from 2012 through 2025, including core installations. Both 32‑bit and 64‑bit architectures are impacted where listed, and the issue spans the broad range of supported Windows releases.
Risk and Exploitability
The EPSS score of less than 1 % indicates that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a local attacker with legitimate user context creating a malicious graphic that the Graphics Component will process. Once the out‑of‑bounds read is triggered, arbitrary code can run with the privileges of the user, making this a local privilege exploitation scenario.
OpenCVE Enrichment