Impact
An integer overflow or wraparound in Windows PDF processing enables an attacker to cause the system to execute arbitrary code when a specially crafted PDF file is processed. The result can be a full compromise of the host, including data theft, modification, and denial of service. This weakness is identified by CWE‑122 and CWE‑190.
Affected Systems
Affected systems include Microsoft Windows 10 starting with the 1607 update, Windows 10 1809, 21H2, 22H2, Windows 11 in the 23H2, 24H2, 25H2, 26H1 releases, and the Windows Server family – Windows Server 2016, 2019, 2022, and 2025, including server‑core installations.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the vulnerability is exploitable over a network according to the description. Although the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests active exploitation may not yet be widespread. Nonetheless, the high rating and network‑based attack vector warrant immediate action.
OpenCVE Enrichment