Impact
A heap-based buffer overflow in the Microsoft Graphics Component can allow an attacker to execute arbitrary code on the target system. The vulnerability occurs when the component processes certain network‑originated data, leading to uncontrolled memory writes. Successful exploitation grants the attacker full code execution privileges on the affected machine, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects multiple Microsoft products, including Microsoft 365 Apps for Enterprise, Microsoft Office 2016/2019/2021/2024/365 for Mac, Office LTSC 2021/2024, as well as Windows 10 build 1607 and later, Windows 11 versions up to 26H1, and Windows Server editions from 2012 through 2025, across both 32‑bit and 64‑bit platforms, including ARM64 variants.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity Remote Control vulnerability. No EPSS score is currently available, so the likelihood of exploitation cannot be quantified from public data, but the vulnerability is not listed in CISA KEV, implying no confirmed exploitation yet. The attack vector is inferred to be network‑based, as the flaw is triggered by unsanitized data received over a network. Attacks would likely require an attacker to supply crafted data to a target system exposing the Graphics Component, after which the attacker can achieve arbitrary code execution.
OpenCVE Enrichment