Microsoft Windows Subsystem for Linux GUI Heap-Based Buffer Overflow Remote Code Execution Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Windows Subsystem for Linux GUI. This vulnerability allows an unauthorized attacker to execute code remotely over a network. The issue arises from the way data is handled in memory, creating an opportunity for exploitation.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Users can download the security update for Windows Subsystem for Linux GUI from the Microsoft GitHub repository. Instructions for updating to the latest version of WSL, which includes WSLg, are also available on the GitHub repository.

Added: Nov 11, 2025, 6:47 PM
Updated: Nov 11, 2025, 6:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.4
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.