PT-2025-32850 · Microsoft · Windows Gdi+1
Gábor Selján
+1
·
Published
2025-08-12
·
Updated
2026-05-22
·
CVE-2025-53766
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows GDI+ (affected versions not specified)
Description
A heap-based buffer overflow exists in Windows GDI+, where a heap-based buffer overflow is a memory corruption issue that occurs when a program writes more data to a heap-allocated memory block than it can hold. This flaw allows an unauthorized remote attacker to execute arbitrary code and gain unauthorized access to protected information by loading a specially crafted metafile or through malicious websites.
Recommendations
Apply the Microsoft August 2025 Patch Tuesday updates.
Fix
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Gdi