Impact
The vulnerability is a heap‑based buffer overflow in the Windows Imaging Component that allows an attacker to execute arbitrary code with system privileges over the network. An adversary can send specially crafted data to the component, resulting in uncontrolled memory writes and immediate code execution. Successful exploitation can lead to full compromise of the host, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects a broad range of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 (both full and Server Core installations). The vulnerability has been documented for both x86 and x64 architectures, as well as ARM64 where applicable.
Risk and Exploitability
The CVSS base score of 8.8 places the issue in the High severity range, rendering any affected system vulnerable to potential compromise. The vulnerability is not listed in the CISA KEV catalog. Attackers would reach the vulnerable component through a network that allows delivery of the malicious payload, such as shared media, Samba shares or other file transfer mechanisms. Given the nature of the exploit—remote code execution—the risk to any affected system is substantial and attackers could cause widespread damage.
OpenCVE Enrichment