Impact
The vulnerability is a heap‑based buffer overflow in the Microsoft Graphics Component, which can be triggered by an unauthorized attacker remotely. This flaw allows the attacker to execute arbitrary code on the affected system, compromising confidentiality, integrity, and availability. The weakness corresponds to CWE‑122. The overflow occurs within the DirectWrite engine and can be invoked over a network connection, enabling remote exploitation without local privileges.
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS data is not available, and the flaw is not currently listed in the CISA KEV catalog, but the lack of a known exploit does not reduce the potential risk for systems that remain unpatched. The attacker can gain remote code execution through network traffic, making it a significant threat for exposed or internet‑connected machines. No publicly disclosed exploitation code is known yet, but due to the severity and the nature of the flaw, a patch should be applied immediately.
OpenCVE Enrichment