cbcvebase.
CVE-2025-53766
published 2025-08-12

CVE-2025-53766: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.18%
93.6th percentile
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
microsoft365_copilot< 16.0.19127.2000016.0.19127.20000
microsoftmicrosoft_office_for_android>= 16.0.1 < 16.0.19127.2000016.0.19127.20000
microsoftmicrosoft_office_for_universal>= 16.0.1 < 16.0.14326.2261816.0.14326.22618
microsoftoffice< 16.0.14326.2261816.0.14326.22618
microsoftwindows_10_1507< 10.0.10240.2110010.0.10240.21100
microsoftwindows_10_1607< 10.0.14393.833010.0.14393.8330
microsoftwindows_10_1809< 10.0.17763.767810.0.17763.7678
microsoftwindows_10_21h2< 10.0.19044.621610.0.19044.6216
microsoftwindows_10_22h2< 10.0.19045.621610.0.19045.6216
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2110010.0.10240.21100
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.833010.0.14393.8330
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.767810.0.17763.7678
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.621610.0.19044.6216
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.621610.0.19045.6216
microsoftwindows_11_22h2< 10.0.22621.576810.0.22621.5768
microsoftwindows_11_23h2< 10.0.22631.576810.0.22631.5768
microsoftwindows_11_24h2< 10.0.26100.485110.0.26100.4851
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.576810.0.22621.5768
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.576810.0.22631.5768
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.576810.0.22631.5768
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.494610.0.26100.4946
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.278726.1.7601.27872
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.234716.0.6003.23471
microsoftwindows_server_2012

Detection & IOCsextracted from sources · hover to see the quote

pathgdiplus!ScanOperation::AlphaDivide_sRGB+0x33
filenameGdiPlus.dll
bytes
Type=0x400B (EmfPlusDrawRects record type)
  • Attack vector is network (AV:N) with no privileges required and no user interaction in the worst-case scenario: an attacker uploads a document containing a specially crafted metafile to a web service that parses it.
  • The Preview Pane is NOT an attack vector for CVE-2025-53766; focus detection on document upload/parsing pipelines and web services processing metafiles.
  • The crash/exploitation call stack involves gdiplus!ScanOperation::AlphaDivide_sRGB — monitor for access violations or crashes in this function within GdiPlus.dll as a potential exploitation indicator.
  • Malformed EMF+ files with EmfPlusDrawRects (record type 0x400B) containing oversized or mismatched Count vs. actual RectData entries (e.g., Count=3 but 7 rect entries present) are a structural indicator of exploit attempts.
  • ·Exploitation requires the target system or web service to parse a document containing a specially crafted metafile; the vulnerability is in Windows GDI+ (GdiPlus.dll) and affects web services parsing such documents even without user interaction.
  • ·As of the MSRC advisory, CVE-2025-53766 has not been publicly disclosed or actively exploited in the wild; exploitability is assessed as 'Exploitation Less Likely'.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.