Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2025-50165: Windows Graphics Component Remote Code Execution Vulnerability

According to the CVSS metric, attack vector is (AV:N) and user interaction is none (UI:N). What does that mean for this vulnerability?

This can happen without user intervention. An attacker can use an uninitialized function pointer being called when decoding a JPEG image. This can be embedded in Office and 3rd party documents/files

Microsoft Security Response Center
#vulnerability#windows#rce#Microsoft Graphics Component#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2025-8882: Chromium: CVE-2025-8882 Use after free in Aura