Impact
Heap-based buffer overflow in the Windows Imaging Component enables an attacker who can send crafted data over a network to gain code execution authority. The flaw allows the attacker to execute arbitrary code with privileges of the affected process, leading to full control of the operating system. This weakness is a classic out‑of‑bounds write, classified as CWE‑122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Core installations) are affected.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network traffic that interacts with the imaging component. Once successfully exploited, the attacker can achieve full system compromise.
OpenCVE Enrichment