Impact
A stack-based buffer overflow in the Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. The flaw resides in DirectWrite processing, and it can be exploited to run arbitrary code with the privileges of the affected process. The weakness corresponds to CWE‑121 and results in a high‑severity compromise where confidentiality, integrity, and availability are threatened.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Microsoft Windows Server 2016 (including Server Core), Server 2019 (including Server Core), Server 2022, and Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 8.8 classifies this as high risk. EPSS data is not available, but the lack of exploitation metrics does not reduce the potential impact. KeV does not list this vulnerability, yet the nature of a remote stack overflow suggests significant attack potential. The likely attack vector is over a network, as described, wherein a maliciously crafted packet or user input triggers the overflow. No prerequisites beyond network reachability are mentioned, so the vulnerability can be exploited from any location that can reach the vulnerable component.
OpenCVE Enrichment