Impact
An out‑of‑bounds write in the Windows Imaging Component (WIC) permits an unauthenticated network attacker to execute arbitrary code on a vulnerable machine. This memory corruption flaw, classified as CWE‑787, bypasses normal input validation in the image processing routines, enabling the attacker to control program flow and gain full control of the operating system. The consequences include complete compromise of confidentiality, integrity, and availability of the affected Windows installation.
Affected Systems
Microsoft Windows operating systems from Windows 10 v1607, Windows 10 v1809, Windows 10 v21H2, Windows 10 v22H2, Windows 11 v23H2, Windows 11 v24H2, Windows 11 v25H2, Windows 11 v26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their core installations, are affected. All builds listed in the CNA data must be considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 9.8 signifies an extremely severe vulnerability with a high likelihood of exploitation. Though the EPSS score is currently unavailable, the lack of a KEV listing does not diminish the risk to organizations that operate the affected Windows versions. The flaw is remotely exploitable over a network, implying that an adversary could launch attacks without local access. Until a patch is applied, adversaries could leverage the vulnerability to install malware, create persistent backdoors, or otherwise take full control of the target systems.
OpenCVE Enrichment