CVE-2025-21338
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 190
Summary
CVE-2025-21338 is a newly disclosed remote code execution vulnerability affecting Microsoft's Graphics Device Interface (GDI+). Maliciously crafted EMF (Enhanced MetaFile) images can exploit this weakness, allowing an attacker to execute arbitrary code on a vulnerable system. Successful exploitation could lead to unauthorized system access, data theft, or further malware infections. Users are advised to update their systems as soon as possible to mitigate this risk. Microsoft has released a patch to address the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows
- Microsoft Windows Server 2008
- Windows Server 2022
Affected Vendors
- Microsoft