Multiple vulnerabilities have been found in Microsoft's Graphics Device Interface (GDI), a core component of the Windows operating system responsible for graphics rendering.

These bugs, identified by Check Pointthrough an intensive fuzzing campaign targeting Enhanced Metafile (EMF) formats, could allow remote attackers to execute arbitrary code or steal sensitive data.
See also: CISA: Linux Kernel vulnerability used for ransomware attacks
The issues were responsibly disclosed to Microsoft and fixed in Patch Tuesday updates in 2025, highlighting the ongoing risks in legacy graphics processing. The vulnerabilities arise from improper handling of EMF+ records , which are used in documents and images processed by applications such as Microsoft Office and web browsers. Attackers could exploit these vulnerabilities by tricking users into opening malicious files , such as modified Word documents or image thumbnails. Ultimately, a complete system compromise could occur without user interaction.
Check Point's analysis highlights how these bugs resulted from invalid rectangle objects, buffer overflows, and incomplete previous fixes. All of which highlight the security challenges of deeply embedded system libraries.

Microsoft Graphics Device Interface: Vulnerabilities
The vulnerability , CVE-2025-30388, rated “Important” with a CVSS score of 8.8, involves out-of-bounds memory operations when processing records such as EmfPlusDrawString and EmfPlusFillRects . Caused by malformed EmfPlusSetTSClip records, it allows attackers to read or write beyond allocated heap buffers, potentially leaking data or allowing code execution. This bug affects Windows 10 and 11, as well as Office for Mac and Android. Microsoft considers its exploitation highly likely, due to its accessibility through common file formats.
See also: Australia: Cisco IOS XE vulnerability exploited to distribute BADCANDY
The most severe vulnerability, CVE-2025-53766 (Critical, CVSS 9.8), allows remote code execution via out-of-bounds writes in the ScanOperation::AlphaDivide_sRGB function. By creating EmfPlusDrawRects records with oversized rectangles, attackers can overflow scan-line buffers in bitmap rendering, bypassing the limits on thumbnail generation. No privileges are required, making the vulnerability ideal for network attacks on services that parse EMF files.
Finally, the vulnerability CVE-2025-47984 (Important, CVSS 7.5) allows information disclosure. It exploits a bug in EMR_STARTDOC record handling, which had received an incomplete fix (CVE-2022-35837). It causes over-reads in string length calculations, exposing adjacent heap memory. Classified as a “ protection mechanism” (CWE-693), this bug could facilitate attacks by revealing system secrets.

Protection
Microsoft has addressed these vulnerabilities in updates to GdiPlus.dll and gdi32full.dll. Users are urged to apply the patches immediately and enable automatic updates. Check Point recommends disabling EMF rendering in untrusted environments, using sandboxed document viewers, and monitoring for strange graphics processing.
See also: New BOF tool exploits Microsoft Teams cookie encryption
These discoveries, part of a fuzzing effort on Windows kernel graphics, reveal how small errors in file parsing can evade detection for years. As remote work and cloud services proliferate, such vulnerabilities pose growing threats to businesses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
