Junglewise Threat Intelligence

CVE-2025-53766: Microsoft Windows GDI+ heap overflow

CVE-2025-53766 · Severity: critical · CVSS 9.8 · Published 2025-08-12

Technologies: Microsoft Office, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A critical vulnerability exists in Windows GDI+, a core component used by Windows and Office to display graphics and images. An attacker could exploit this flaw over a network to gain full control of a system without any user interaction or login credentials. This poses a severe risk to data confidentiality, system integrity, and overall business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows GDI+ component, which handles graphics rendering for the operating system and various applications. The vulnerability is exploitable over the network without authentication or user interaction (AV:N/AC:L/PR:N/UI:N). By sending specially crafted data to a system that processes it via GDI+, an attacker can trigger the overflow to achieve remote code execution (RCE). Microsoft has released security updates to address this issue across affected versions of Windows, Windows Server, and Microsoft Office for Android.

Affected products

  • Microsoft Windows 10 Up to (excluding) 10.0.19045.6216
  • Microsoft Windows 11 Up to (excluding) 10.0.26100.4851
  • Microsoft Windows Server 2025 Up to (excluding) 10.0.26100.4851
  • Microsoft Windows Server 2022 Up to (excluding) 10.0.20348.3989
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2016 Up to (excluding) 10.0.14393.8330
  • Microsoft Office Android versions up to (excluding) 16.0.19127.20000

Timeline

  • 2025-08-12: advisory: Initial advisory published by Microsoft and NVD
  • 2025-05-22: other: NVD record modified with updated CPE configurations

References

Related threats