Impact
A heap-based buffer overflow exists within Windows GDI+ that permits an attacker who already has local user privileges to execute arbitrary code on the affected system. The flaw arises during processing of certain graphics data and can be leveraged to gain elevated rights, thus compromising confidentiality, integrity, and availability of the machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including core installations. All listed releases are potentially impacted by the vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high impact for a local attacker. EPSS data is not available, but the flaw is not currently listed in CISA’s KEV catalog. The likely attack vector is local: an authorized user who can run a crafted image or graphics-related application may trigger the overflow to execute code with the privileges of that user, potentially escalating privileges to administrative levels.
OpenCVE Enrichment