Impact
A heap‑based buffer overflow exists in the Windows Imaging Component. The flaw permits an unauthenticated attacker to execute arbitrary code on the target system, giving full control over the compromised machine when the failure occurs.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012 through 2025, including the common Server Core installations. The vulnerability applies to both 32‑bit and 64‑bit builds of these operating systems as listed in the vendor’s documented affected‑version set.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as High. Although the EPSS score is not available, the absence of a public KEV listing suggests no known widespread exploitation yet. Based on the description, the likely attack vector is network‑based: an attacker can trigger the vulnerability by interacting with the Imaging Component over the network, enabling remote code execution. No specific prerequisites beyond the presence of the vulnerable component are listed in the data.
OpenCVE Enrichment