CVE-2022-33635

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-33635 is a Remote Code Execution vulnerability affecting Microsoft Windows and its GDI+ component. An attacker can exploit this weakness by sending a specially crafted EMF (Enhanced MetaFile) image to a victim via email or through a malicious website. Successful exploitation results in the attacker gaining the same user privileges as the current Windows user, potentially leading to significant security breaches and system compromise. Microsoft released a security update to address this issue, and users are strongly encouraged to install it as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 7
  • Microsoft Windows Server 2008
  • Microsoft Windows 10
  • Microsoft Windows Server 2012
  • Microsoft Windows 8.1

Affected Vendors

  • Microsoft