Microsoft Windows GDI+ Buffer Over-Read Vulnerability Leading to Denial-of-Service

Vulnerability

A buffer over-read vulnerability has been identified in Windows GDI+ that allows an unauthorized attacker to cause a denial-of-service condition over the network. This vulnerability affects multiple Windows versions and stems from improper handling of buffer data, which can be exploited to disrupt service availability.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing a significant disruption in service availability.

Remediation

Users can apply the security update KB5075999 to address this vulnerability. This update is available through the Microsoft Update Catalog. For Windows 10 Version 22H2, the update can be downloaded via the Monthly Rollup KB5075912. Windows Server 2022 users can also apply the Security Update KB5075906. For Windows 11, the Security Update KB5077181 is available for both x64 and ARM64-based systems. Windows Server 2019 users can apply the Security Update KB5075904.

Added: Feb 10, 2026, 8:03 PM
Updated: Feb 11, 2026, 2:16 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
2.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.