PT-2024-4966 · Microsoft · Windows Imaging+1

George Holmes

·

Published

2024-07-09

·

Updated

2025-07-27

·

CVE-2024-38060

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Imaging Component (affected versions not specified)
Description This vulnerability allows remote attackers to execute arbitrary code and affect the system. The issue is a buffer overflow in dynamically allocated memory within the Windows Imaging Component (WIC) framework. Exploitation may allow an attacker to execute arbitrary code remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05490
CVE-2024-38060

Affected Products

Windows
Windows Imaging