A critical remote code execution vulnerability in Windows Graphics Component allows attackers to take control of a system via specially crafted JPEG images.
See also: Turn the transition to Windows 11 into a security opportunity

With a CVSS score of 9.8, this vulnerability poses a serious threat to Windows users worldwide, as it requires no user action to be exploited.
The vulnerability was discovered in May 2025 and patched by Microsoft on August 12, 2025. It results from an untrusted pointer dereference in the windowscodecs.dll, which affects key image processing functions. Attackers can embed the malicious JPEG in common files, such as Microsoft Office documents, causing a silent breach once the file is opened or previewed.
This vulnerability highlights the ongoing risks in older graphics processing systems, where even simply decoding an image can lead to a complete system takeover. With Windows running on billions of devices, unpatched systems remain particularly vulnerable to phishing attacks or malicious downloads.
See also: Microsoft Patch Tuesday November 2025: Fixes 63 vulnerabilities

Zscaler's ThreatLabz discovered the vulnerability through targeted fuzzing in the Windows Imaging Component, focusing on the JPEG encoding and decoding paths within windowscodecs.dll .
The entry point for the exploit is in the GpReadOnlyMemoryStream::InitFile, where the tampered buffer size values allow attackers to control memory snapshots during file mapping.
Fuzzing revealed a bug caused by dereferencing an uninitialized pointer at address jpeg_finish_compress+0xcc, which exposes data that can be inspected by the user via heap spraying techniques.
WinDbg analysis, through stack traces, indicated critical functions such as CJpegTurboFrameEncode::HrWriteSource and CFrameEncodeBase::WriteSource, confirming that the vulnerability is located in the JPEG metadata encoding processes.
See also: Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

This uninitialized resource issue allows arbitrary code execution without privileges, making the vulnerability exploitable even over a network. Microsoft confirmed that the bug affects automatic image rendering in applications that rely on the Graphics Component.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
