CVE-2025-50176Heap-based Buffer Overflow in Microsoft Windows 11 Version 22h2

Severity
7.8HIGHNVD
EPSS
0.2%
top 62.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

NVDmicrosoft/windows< 10.0.20348.3989+2
NVDmicrosoft/windows_11_22h2< 10.0.22621.5768
NVDmicrosoft/windows_11_23h2< 10.0.22631.5768
NVDmicrosoft/windows_11_24h2< 10.0.26100.4851
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4052

🔴Vulnerability Details

2
CVEList
DirectX Graphics Kernel Remote Code Execution Vulnerability2025-08-12
GHSA
GHSA-m3h5-fxqj-23wf: Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally2025-08-12

📋Vendor Advisories

1
Microsoft
DirectX Graphics Kernel Remote Code Execution Vulnerability2025-08-12

🕵️Threat Intelligence

6
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review | Qualys2025-08-12
Talos
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities2025-08-12
Talos
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review2025-08-12
CVE-2025-50176 — Heap-based Buffer Overflow | cvebase