logo

CVE-2025-50165: Windows Graphics Component Flaw

ID: b143a245-1775-5d2a-96ad-5fac379a5d08

STIX ID: report--b143a245-1775-5d2a-96ad-5fac379a5d08

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-01

Date Updated: 2026-05-01

...
...

ThreatLabz analyzes CVE-2025-50165, a WindowsCodecs JPEG parsing vulnerability that allows an attacker to control an uninitialized function pointer via crafted JPEGs; the report covers discovery via fuzzing, crash triage with WinDbg, exploitation using heap spraying and ROP to achieve RCE, and provides a PoC application demonstrating the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.