Impact
The vulnerability is an integer overflow or wraparound in the Windows GDI+ graphics subsystem. An attacker can exploit this flaw by sending specially crafted data over the network, which allows arbitrary code execution with no authentication. The weakness is characterized by CWE-122 (Heap-based Buffer Overflow) and CWE-190 (Integer Overflow or Wraparound).
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 build 1607, 1809, 21H2 and 22H2; Windows 11 build 23H2, 24H2, 25H2 and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity assessment. EPSS data is currently unavailable, so the actual likelihood of exploitation cannot be quantified; however, the vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. The attack vector is inferred to be network‑based, as the flaw permits code execution through network‑sent data. An unauthenticated attacker can trigger the flaw remotely, posing a significant threat to exposed systems.
OpenCVE Enrichment