CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-53766

CVSS 9.8v3.1pub. 2025-08-12upd. 2025-08-14

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The bug is a heap-based buffer overflow (CWE-122) in the Windows GDI+ library. An attacker sends specially crafted data over the network that causes data to be written beyond the reserved memory area. This can enable overwriting control structures in the process memory and consequently redirect code execution to a malicious payload. The attack requires no authentication or any user interaction.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code remotely (RCE) in the context of the process handling GDI+, which can lead to complete system compromise, loss of confidentiality, integrity, and availability of data.

Mitigation & patch

Patches available from the vendor should be applied immediately in accordance with references published in the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53766

Who is affected

Microsoft Windows 11 22H2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Office

    APP
    Microsoft
    < 16.0.14326.22618< 16.0.19127.20000
  • Microsoft Windows 10 1507

    OS
    Microsoft
    < 10.0.10240.21100
  • Microsoft Windows 10 1607

    OS
    Microsoft
    < 10.0.14393.8330
  • Microsoft Windows 10 1809

    OS
    Microsoft
    < 10.0.17763.7678
  • Microsoft Windows 10 21h2

    OS
    Microsoft
    < 10.0.19044.6216
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    < 10.0.19045.6216
  • Microsoft Windows 11 22h2

    OS
    Microsoft
    < 10.0.22621.5768
  • Microsoft Windows 11 23h2

    OS
    Microsoft
    < 10.0.22631.5768
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.4851
  • Microsoft Windows Server 2008

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2012

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2016

    OS
    Microsoft
    < 10.0.14393.8330
  • Microsoft Windows Server 2019

    OS
    Microsoft
    < 10.0.17763.7678
  • Microsoft Windows Server 2022

    OS
    Microsoft
    < 10.0.20348.3989
  • Microsoft Windows Server 2022 23h2

    OS
    Microsoft
    < 10.0.25398.1791
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.4851
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2023-23397CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność privilege escalation w Microsoft Outlook (CVE-2023-23397)

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)

CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product

RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa