Impact
A heap‑based buffer overflow exists in the Windows Raw Image Extension that allows an unauthorized attacker to execute arbitrary code. The flaw is a classic out‑of‑bounds write (CWE‑122) that can lead to full system compromise when triggered. The impact is severe, potentially granting an attacker full control and affecting confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Microsoft’s Raw Image Extension on Windows platforms. Exact version numbers are not provided in the public data, so any installation of the extension that has not yet received a Microsoft security update is considered at risk.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity, but the EPSS score is not available so the probability of exploitation cannot be quantified. The flaw is not currently listed in the CISA KEV catalog. The likely attack vector is remote network traffic directed to the Raw Image Extension, where an attacker can deliver crafted data to trigger the overflow.
OpenCVE Enrichment