Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image
ID: 9db154c2-fef6-5412-94b4-90346b7ef033
STIX ID: report--9db154c2-fef6-5412-94b4-90346b7ef033
Feed Name: cybersecurityNews.com
**Critical RCE in Windows Graphics Component (CVE-2025-50165)** — A CVSS 9.8 remote code execution flaw in windowscodecs.dll enables attackers to achieve arbitrary code execution by delivering specially crafted JPEGs (including embedded in Office documents) that trigger an uninitialized pointer dereference and heap-spray-based ROP chains; Microsoft released patches on August 12, 2025 for affected builds and vendors recommend immediate patching, disabling image previews for untrusted files, and sandboxing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
