Impact
A heap‑based buffer overflow in Microsoft Graphics Component allows an attacker who already has local execution rights to run arbitrary code within the context of the affected user. The weakness is categorized as CWE‑122 (Heap‑Based Buffer Overflow) and CWE‑190 (Integer Overflow). This can lead to system compromise, privilege escalation, persistence, or malware deployment.
Affected Systems
This flaw affects multiple Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and server core installations.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score is not available, suggesting limited known exploitation activity. The CVE is not listed in the CISA KEV catalog. The likely attack vector is local code execution; an attacker who can run code locally—such as from a compromised user session or physical access—can trigger the overflow to execute arbitrary instructions. This limitation reduces remote exposure but still presents a significant risk to systems where privileged users are present or where local privileges are widely granted.
OpenCVE Enrichment