Executive brief
A security vulnerability exists in the Windows Imaging Component, a system tool used by Windows and Office to process and display digital images. An attacker could exploit this flaw to gain access to sensitive information stored in the computer's memory that should otherwise be protected. To carry out the attack, a user would typically need to be tricked into opening a specially crafted file or running a malicious application locally on the device.
Technical details
A vulnerability classified as 'Use of Uninitialized Resource' (CWE-908) exists within the Windows Imaging Component (WIC). The flaw occurs when the component fails to properly initialize memory buffers before use, potentially allowing a local attacker to read the contents of uninitialized memory. Exploitation requires local access and typically involves user interaction, such as convincing a target to open a malicious image file. Successful exploitation results in a loss of confidentiality, as the attacker can disclose sensitive information from the process memory. Microsoft has released security updates to address this issue across affected Windows and Office versions.
Affected products
- Microsoft Windows 10 All versions up to 22H2
- Microsoft Windows 11 22H2, 23H2, 24H2
- Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 2025
- Microsoft Office / 365 Copilot Android versions prior to 16.0.19220.20000
Timeline
- 2025-09-09: disclosed: Initial disclosure by Microsoft
- 2025-09-09: advisory: MSRC advisory published