logo

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

ID: 9db154c2-fef6-5412-94b4-90346b7ef033

STIX ID: report--9db154c2-fef6-5412-94b4-90346b7ef033

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Critical RCE in Windows Graphics Component (CVE-2025-50165)** — A CVSS 9.8 remote code execution flaw in windowscodecs.dll enables attackers to achieve arbitrary code execution by delivering specially crafted JPEGs (including embedded in Office documents) that trigger an uninitialized pointer dereference and heap-spray-based ROP chains; Microsoft released patches on August 12, 2025 for affected builds and vendors recommend immediate patching, disabling image previews for untrusted files, and sandboxing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.