Impact
An integer overflow or wraparound condition within the Windows Imaging Component allows an unauthorized attacker to execute code through the network. The flaw originates from improper handling of numerical values during image processing, enabling malicious input to control memory addresses and consequently run arbitrary code. The consequence is a full compromise of the affected system, granting the attacker complete control and the ability to exfiltrate data, install malware, or pivot within the network.
Affected Systems
The vulnerability impacts a broad range of Windows products, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, covering both standard and Server Core installations. All affected releases expose the Windows Imaging Component to network input, making them susceptible if the component is reachable remotely.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending crafted image data over the network to the Imaging Component, such as via shared folders or SMB protocols. Based on the description, exploitation requires only network access and does not need elevated privileges, making it a realistic threat for attackers who can reach the target environment.
OpenCVE Enrichment