Executive brief
A critical vulnerability exists in Windows GDI+, a core component used by Windows and Office to display graphics and images. An attacker could exploit this flaw over a network to gain full control of a system without any user interaction or login credentials. This poses a severe risk to data confidentiality, system integrity, and overall business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows GDI+ component, which handles graphics rendering for the operating system and various applications. The vulnerability is exploitable over the network without authentication or user interaction (AV:N/AC:L/PR:N/UI:N). By sending specially crafted data to a system that processes it via GDI+, an attacker can trigger the overflow to achieve remote code execution (RCE). Microsoft has released security updates to address this issue across affected versions of Windows, Windows Server, and Microsoft Office for Android.
Affected products
- Microsoft Windows 10 Up to (excluding) 10.0.19045.6216
- Microsoft Windows 11 Up to (excluding) 10.0.26100.4851
- Microsoft Windows Server 2025 Up to (excluding) 10.0.26100.4851
- Microsoft Windows Server 2022 Up to (excluding) 10.0.20348.3989
- Microsoft Windows Server 2019
- Microsoft Windows Server 2016 Up to (excluding) 10.0.14393.8330
- Microsoft Office Android versions up to (excluding) 16.0.19127.20000
Timeline
- 2025-08-12: advisory: Initial advisory published by Microsoft and NVD
- 2025-05-22: other: NVD record modified with updated CPE configurations