Impact
An integer underflow in Windows GDI+ can be abused by an authorized attacker to elevate their privileges when interacting over a network. The flaw allows a controlled wrap around of internal counters or sizes, leading to unauthorized access to protected resources. This privilege escalation could enable local or remote users to gain higher-level rights on the affected system.
Affected Systems
Affected Microsoft Windows releases include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, 2025, with both full and Server Core installations for the 2012 family. All variants of these platforms are impacted, so any systems running them are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8, indicating a high risk of exploitation. Although EPSS is not available, the lack of listing in the CISA KEV catalog does not diminish the severity or the potential for exploitation. The likely attack vector is remote exploitation via network interactions that invoke GDI+ functions, and the vulnerability can be leveraged by attackers who already have legitimate or authenticated access over the network.
OpenCVE Enrichment