CVE-2025-53766

Published Aug 12, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-53766 is a heap-based buffer overflow vulnerability affecting Windows GDI+ (Graphics Device Interface Plus). It was discovered and disclosed in August 2025 and impacts multiple versions of Microsoft Windows, including Windows Server 2008 through 2025, and Windows 10 through Windows 11. The vulnerability allows an unauthorized attacker to execute code over a network. Exploitation is possible through specially crafted metafiles in documents, and can be triggered through document processing on web services without user interaction.

Description
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
365_copilot, office, windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending
  1. Windows graphics... #CVE-2025-30388 and CVE-2025-53766 #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. https://t.co/5eGabQcOJG

    @CaponeSoc

    9 Dec 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️Vulnerabilidades en productos Microsoft ❗CVE-2025-53766 ❗CVE-2025-30388 ❗CVE-2025-47984 ➡️Más info: https://t.co/wKQpMAyOv2 https://t.co/P8dK0N5dOx

    @CERTpy

    13 Nov 2025

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔴 Microsoft GDI Vulnerabilities: Graphics Parser RCE & Info Leak Check Point Research uncovered three GDI flaws where crafted EMF+ metafiles trigger out-of-bounds memory ops in GdiPlus.dll. CVE-2025-30388 (important) and CVE-2025-53766 (critical RCE) exploit the rendering

    @the_c_protocol

    3 Nov 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 We uncovered #security #vulnerabilities in #Windows graphics. #CVE-2025-30388 and CVE-2025-53766 are #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. 👇https://t.co/mK5qUol34V

    @_CPResearch_

    3 Nov 2025

    8445 Impressions

    37 Retweets

    75 Likes

    33 Bookmarks

    0 Replies

    2 Quotes

  5. Microsoft just rolled out updates for August 2025, patching over 100 vulnerabilities! Among them, CVE-2025-53766 stands out with a critical score of 9.8. Stay vigilant—malicious ads are a threat! How do you ensure your systems stay secure? #Cybersecurity #Ciberseguridad https:

    @CyberDailyPost

    23 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️Actualizaciones de seguridad de Microsoft ❗CVE-2025-53766 ❗CVE-2025-50165 ❗CVE-2025-50171 ➡️Más info: https://t.co/PUM5sZp4pl https://t.co/fxesUeGgL5

    @CERTpy

    19 Aug 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🇺🇸 - CYBERSÉCURITÉ / ÉTATS-UNIS 🔸 Microsoft a corrigé plus de 100 vulnérabilités dont des critiques comme CVE-2025-53766. Adobe a également mis à jour près de 70 produits. https://t.co/RrXHSd0Ot8

    @nexus_osint

    14 Aug 2025

    1696 Impressions

    3 Retweets

    31 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. 今月気になるのは、Webページを開いただけでコード実行の脆弱性(CVE-2025-53766 )や画像を閲覧しただけでコード実行の脆弱性(CVE-2025-50165)、また悪用されそうなSharePointのRCE(CVE-2025-49712)あたりですね。 The

    @autumn_good_35

    13 Aug 2025

    1130 Impressions

    2 Retweets

    12 Likes

    4 Bookmarks

    1 Reply

    0 Quotes

  9. 🚨 Attention, admins! A heap overflow vulnerability (CVE-2025-53766) in GDI+ could let remote code execution crash your party. Verify patches with Microsoft before you hit the panic button! #WindowsForum #CyberSecurity #PatchItUp https://t.co/fvzoxhzX6V

    @windowsforum

    12 Aug 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. [CVE-2025-53766: CRITICAL] Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.#cve,CVE-2025-53766,#cybersecurity https://t.co/HcdFfPplap https://t.co/rDRHVpH2rp

    @CveFindCom

    12 Aug 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.