CVE-2025-21338
Published: 14 January 2025
Description
GDI+ Remote Code Execution Vulnerability
Security Summary
CVE-2025-21338 is a GDI+ Remote Code Execution vulnerability, published on 2025-01-14, with a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). It is associated with CWE-190 and affects the GDI+ graphics component in Microsoft Windows systems.
The vulnerability can be exploited by a local attacker who has low privileges on the target system. Exploitation requires low complexity and no user interaction, allowing the attacker to execute arbitrary code in the context of the affected process, with high impacts on confidentiality, integrity, and availability.
Microsoft's advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21338 provides details on patches and mitigation steps for addressing this vulnerability.
Details
- CWE(s)