Executive brief
A critical vulnerability exists in the Microsoft Graphics Component, which handles how images and visual elements are displayed across Windows and Office applications. An unauthorized attacker could exploit this flaw over a network to take full control of an affected system without any user interaction. This poses a severe risk to data confidentiality, system integrity, and overall business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Microsoft Graphics Component. The vulnerability is triggered when the component improperly handles specially crafted data, leading to memory corruption. An attacker can exploit this over the network without requiring any prior authentication or user interaction (UI:N). Successful exploitation allows for remote code execution (RCE) in the context of the affected process. The flaw impacts a wide range of Microsoft products including various versions of Windows, Windows Server, and Microsoft Office on Android and macOS. Security updates are available through the Microsoft Security Response Center.
Affected products
- Microsoft Windows 10, 11, Server 2008, 2012, 2016, 2019, 2022, 2025
- Microsoft Office Android, macOS LTSC 2021/2024
Timeline
- 2025-11-11: disclosed
- 2025-11-11: advisory: Initial advisory published by Microsoft