CVE-2025-21338

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 190

Summary

CVE-2025-21338 is a newly disclosed remote code execution vulnerability affecting Microsoft's Graphics Device Interface (GDI+). Maliciously crafted EMF (Enhanced MetaFile) images can exploit this weakness, allowing an attacker to execute arbitrary code on a vulnerable system. Successful exploitation could lead to unauthorized system access, data theft, or further malware infections. Users are advised to update their systems as soon as possible to mitigate this risk. Microsoft has released a patch to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows
  • Microsoft Windows Server 2008
  • Windows Server 2022

Affected Vendors

  • Microsoft