AI description
CVE-2025-53766 is a heap-based buffer overflow vulnerability affecting Windows GDI+ (Graphics Device Interface Plus). It was discovered and disclosed in August 2025 and impacts multiple versions of Microsoft Windows, including Windows Server 2008 through 2025, and Windows 10 through Windows 11. The vulnerability allows an unauthorized attacker to execute code over a network. Exploitation is possible through specially crafted metafiles in documents, and can be triggered through document processing on web services without user interaction.
- Description
- Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- 365_copilot, office, windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- secure@microsoft.com
- CWE-122
- Hype score
- Not currently trending
Windows graphics... #CVE-2025-30388 and CVE-2025-53766 #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. https://t.co/5eGabQcOJG
@CaponeSoc
9 Dec 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidades en productos Microsoft ❗CVE-2025-53766 ❗CVE-2025-30388 ❗CVE-2025-47984 ➡️Más info: https://t.co/wKQpMAyOv2 https://t.co/P8dK0N5dOx
@CERTpy
13 Nov 2025
108 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Microsoft GDI Vulnerabilities: Graphics Parser RCE & Info Leak Check Point Research uncovered three GDI flaws where crafted EMF+ metafiles trigger out-of-bounds memory ops in GdiPlus.dll. CVE-2025-30388 (important) and CVE-2025-53766 (critical RCE) exploit the rendering
@the_c_protocol
3 Nov 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 We uncovered #security #vulnerabilities in #Windows graphics. #CVE-2025-30388 and CVE-2025-53766 are #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. 👇https://t.co/mK5qUol34V
@_CPResearch_
3 Nov 2025
8445 Impressions
37 Retweets
75 Likes
33 Bookmarks
0 Replies
2 Quotes
Microsoft just rolled out updates for August 2025, patching over 100 vulnerabilities! Among them, CVE-2025-53766 stands out with a critical score of 9.8. Stay vigilant—malicious ads are a threat! How do you ensure your systems stay secure? #Cybersecurity #Ciberseguridad https:
@CyberDailyPost
23 Aug 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Actualizaciones de seguridad de Microsoft ❗CVE-2025-53766 ❗CVE-2025-50165 ❗CVE-2025-50171 ➡️Más info: https://t.co/PUM5sZp4pl https://t.co/fxesUeGgL5
@CERTpy
19 Aug 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🇺🇸 - CYBERSÉCURITÉ / ÉTATS-UNIS 🔸 Microsoft a corrigé plus de 100 vulnérabilités dont des critiques comme CVE-2025-53766. Adobe a également mis à jour près de 70 produits. https://t.co/RrXHSd0Ot8
@nexus_osint
14 Aug 2025
1696 Impressions
3 Retweets
31 Likes
1 Bookmark
0 Replies
0 Quotes
今月気になるのは、Webページを開いただけでコード実行の脆弱性(CVE-2025-53766 )や画像を閲覧しただけでコード実行の脆弱性(CVE-2025-50165)、また悪用されそうなSharePointのRCE(CVE-2025-49712)あたりですね。 The
@autumn_good_35
13 Aug 2025
1130 Impressions
2 Retweets
12 Likes
4 Bookmarks
1 Reply
0 Quotes
🚨 Attention, admins! A heap overflow vulnerability (CVE-2025-53766) in GDI+ could let remote code execution crash your party. Verify patches with Microsoft before you hit the panic button! #WindowsForum #CyberSecurity #PatchItUp https://t.co/fvzoxhzX6V
@windowsforum
12 Aug 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-53766: CRITICAL] Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.#cve,CVE-2025-53766,#cybersecurity https://t.co/HcdFfPplap https://t.co/rDRHVpH2rp
@CveFindCom
12 Aug 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*",
"matchCriteriaId": "BEAE985A-74CD-4848-9A69-16C03868EBC7",
"versionEndExcluding": "16.0.19127.20000",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office:*:*:*:*:*:universal:*:*",
"matchCriteriaId": "61108CED-2EB0-4CA4-BA2C-4C8526F1C95B",
"versionEndExcluding": "16.0.14326.22618",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "29F441C0-F0F8-463F-B141-6A33EBA06B1D",
"versionEndExcluding": "10.0.10240.21100",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "5C7C5886-496D-4CBA-956A-A097AC7535D4",
"versionEndExcluding": "10.0.10240.21100",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "4E2D87DA-8EFF-4BB0-B025-A13C3F523BD1",
"versionEndExcluding": "10.0.14393.8330",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "C28DF998-E700-4675-9737-40A53288F54C",
"versionEndExcluding": "10.0.14393.8330",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "3A513AB8-ED03-4BCF-8077-09A117254263",
"versionEndExcluding": "10.0.17763.7678",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "47A8837D-AB4B-465B-8D1C-B89B4EDDBDD4",
"versionEndExcluding": "10.0.17763.7678",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77A19D12-C137-4E01-AF99-E1E7BBC9F0C3",
"versionEndExcluding": "10.0.19044.6216",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "44D27317-F93F-418E-8EC6-9BD1256677C9",
"versionEndExcluding": "10.0.19045.6216",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B07546D0-ED2A-4B93-83E7-EA808DC39724",
"versionEndExcluding": "10.0.22621.5768",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "49E4DFC9-7EB4-4577-83C0-D1E94C2A8D97",
"versionEndExcluding": "10.0.22631.5768",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6376F067-CC36-4A7B-914B-0A60EFF1AC48",
"versionEndExcluding": "10.0.26100.4851",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
"matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
"matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
"matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CD31CC61-6C1C-4232-87D7-E5B4FEBB1276",
"versionEndExcluding": "10.0.14393.8330",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D224ABEA-CCE3-4D7D-86B5-5BEDBF83303B",
"versionEndExcluding": "10.0.17763.7678",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F752199D-6C01-4D8E-BD6C-3031E5CAED20",
"versionEndExcluding": "10.0.20348.3989",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "94E45649-92F4-4D4C-9D94-275506530222",
"versionEndExcluding": "10.0.25398.1791",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B75BE97E-C12D-4DFB-B5F2-B8BF90C3E64E",
"versionEndExcluding": "10.0.26100.4851",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]