Impact
This vulnerability is a heap‑based buffer overflow in Windows Paint that allows an attacker to execute arbitrary code on a target system. The flaw can be triggered when the application processes a maliciously crafted image file received over a network. An attacker who exploits this flaw would gain the privileges of the Paint process, potentially enabling further lateral movement or full system compromise. The weakness is identified as CWE-122.
Affected Systems
The affected products include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 (including their Server Core installations). These operating systems are represented by the Microsoft CPE entries, covering both 32‑bit and 64‑bit builds where indicated.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has yet been observed. Nevertheless, the remote nature of the attack and the lack of mitigations within Paint make the flaw exploitable over a network. The likely attack vector is through delivery of a malicious image file, allowing an attacker to gain code execution with the privileges of the local user running Paint.
OpenCVE Enrichment