Microsoft Windows Imaging Component Information Disclosure Vulnerability

Vulnerability

A vulnerability in the Windows Imaging Component (WIC) has been identified, allowing unauthorized attackers to disclose information locally. This issue arises from the use of uninitialized resources, which could enable an attacker to read small portions of heap memory.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. Security update KB5065429 is available for various Windows 10 versions, while KB5065426 can be downloaded for Windows Server 2025. For Windows Server 2022, 23H2 Edition, the security update KB5065432 is available. Additionally, Windows 11 users can download the security update KB5065431 for both the 22H2 and 24H2 versions. For Windows Server 2022, the security update KB5065432 is also available.

Added: Sep 9, 2025, 6:55 PM
Updated: Sep 9, 2025, 6:55 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.