logo

Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+

ID: 59bf3741-ea44-56f6-87e6-bc9ca89735d1

STIX ID: report--59bf3741-ea44-56f6-87e6-bc9ca89735d1

Feed Name: McAfee Labs Blog

Threat Score
65/100

Date Published: 2021-06-28

Date Updated: 2026-04-28

Author: Hardik Shah

...
...

This report documents McAfee's discovery and root-cause analysis of CVE-2021-1665 — a GDI+ Remote Code Execution vulnerability triggered by malformed EmfPlusDrawString records. It explains how WinAFL fuzzing produced a PoC that caused a heap/object corruption loop (due to an unchecked BuiltLine::GetUntrimmedCharacterCount return value), shows how patch diffing and debugging identified the fix (an added check and destructor), and recommends applying Microsoft updates to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.