CVE-2025-50165

9.8

Microsoft · Windows Graphics Component

A critical untrusted pointer dereference vulnerability in the Microsoft Graphics Component enables unauthenticated attackers to achieve remote code execution over a network.

Executive summary

An unauthenticated remote code execution vulnerability in the Microsoft Graphics Component poses a critical risk to Windows 11 and Server 2025 systems.

Vulnerability

This flaw involves an untrusted pointer dereference (CWE-822) and use of uninitialized resources (CWE-908) within the Graphics Component, which can be triggered by an unauthenticated attacker to execute arbitrary code.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected system without requiring user interaction or authentication. Given the CVSS score of 9.8, this represents a critical risk of complete system compromise, data theft, and potential lateral movement within the network. Immediate remediation is required to prevent unauthorized access and maintain business continuity.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft for the affected Windows versions to move beyond build 10.0.26100.4946.

Proactive Monitoring: Review system event logs for unexpected crashes or errors related to graphics driver processes and monitor network traffic for anomalous inbound connections targeting graphics-related services.

Compensating Controls: Ensure that Windows Firewall or perimeter network security controls are configured to restrict unnecessary inbound traffic to sensitive server assets, which may limit the attack surface.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository FelineKeeper/CVE-2025-50165-Windows-Graphics-Component-RCE.

Analyst recommendation

Due to the critical nature of this remote code execution vulnerability and the existence of a public proof-of-concept, administrators must prioritize patching the affected Windows systems immediately. Failure to update will leave endpoints and servers exposed to potential exploitation by unauthenticated actors. Ensure all security patches are deployed as part of the next maintenance cycle or via emergency out-of-band updates.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written
  5. Fix documented version 10.0.26100.4946 per CVE record

Sources