CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-60724

CVSS 9.8v3.1pub. 2025-11-11upd. 2025-11-17

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The vulnerability is a heap-based buffer overflow (CWE-122) in Microsoft Graphics Component. An attacker can send specially crafted data over the network, causing data to be written outside the bounds of the allocated buffer. As a result of memory overwrite, an attacker may gain control over the process execution flow and execute arbitrary code.

Impact

An unauthenticated attacker operating remotely over the network can execute arbitrary code on the vulnerable system, which may lead to complete takeover of the server or workstation, and violation of system confidentiality, integrity, and availability.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60724). Until the update is installed, it is recommended to limit network exposure of vulnerable systems and monitor network traffic directed to graphics components.

Who is affected

Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025, Microsoft Windows 10 22H2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Office

    APP
    Microsoft
    < 16.0.19426.20044
  • Microsoft Office Long Term Servicing Channel

    APP
    Microsoft
    20212024
  • Microsoft Windows 10 1607

    OS
    Microsoft
    < 10.0.14393.8594
  • Microsoft Windows 10 1809

    OS
    Microsoft
    < 10.0.17763.8027
  • Microsoft Windows 10 21h2

    OS
    Microsoft
    < 10.0.19044.6575
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    < 10.0.19045.6575
  • Microsoft Windows 11 23h2

    OS
    Microsoft
    < 10.0.22631.6199
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.7092
  • Microsoft Windows 11 25h2

    OS
    Microsoft
    < 10.0.26200.7092
  • Microsoft Windows Server 2008

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2012

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2016

    OS
    Microsoft
    < 10.0.14393.8594
  • Microsoft Windows Server 2019

    OS
    Microsoft
    < 10.0.17763.8027
  • Microsoft Windows Server 2022

    OS
    Microsoft
    < 10.0.20348.4346
  • Microsoft Windows Server 2022 23h2

    OS
    Microsoft
    < 10.0.25398.1965
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.7092
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2024-21413CRITICAL9.8⚠ KEVPL ✓same product

RCE w Microsoft Outlook — podatność MonikerLink (CVE-2024-21413)

CVE-2023-23397CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność privilege escalation w Microsoft Outlook (CVE-2023-23397)

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)