Impact
A heap‑based buffer overflow exists in the Windows Imaging Component, allowing an attacker to execute arbitrary code by supplying malicious image data over a network. The flaw can be triggered without local privileges, leading to full compromise of the targeted system and lateral movement if the attacker is part of the same network. This violation of confidentiality, integrity, and availability is consistent with the CWE‑122 classification of buffer overflows.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including their server‑core installations) are listed as affected. All identified builds should be assessed and patched accordingly.
Risk and Exploitability
The CVSS base score of 8.8 places the vulnerability at high risk, and the description confirms it can be abused across a network without authentication. EPSS data is not available, and the flaw is not yet listed in CISA KEV, but the attack surface and critical impact warrant close attention. An adversary with network access could trigger the overflow by crafting a payload within a supported image file format, suggesting that untrusted image input is a nominal vector.
OpenCVE Enrichment