CNNVD-202508-1241 Information
CNNVD ID
CNNVD-202508-1241
Related CVE
- CNNVD Published: 2025-08-12
Description (Chinese)
Microsoft Windows GDI+是美国微软(Microsoft)公司的一个Windows操作操作系统的图形设备接口。该软件是.NET框架的组成部分,负责在屏幕和打印机上绘制图形图像和显示信息。 Microsoft Windows GDI+存在安全漏洞。攻击者利用该漏洞可以执行代码。以下产品和版本受到影响:Windows Server 2019,Windows Server 2019 (Server Core installation),Windows Server 2022,Windows Server 2022 (Server Core installation),Windows 10 Version 21H2 for 32-bit Systems,Windows 10 Version 21H2 for ARM64-based Systems,Windows 10 Version 21H2 for x64-based Systems,Windows 11 Version 22H2 for ARM64-based Systems,Windows 11 Version 22H2 for x64-based Systems,Windows 10 Version 22H2 for x64-based Systems,Windows 10 Version 22H2 for ARM64-based Systems,Windows 10 Version 22H2 for 32-bit Systems,Windows Server 2025 (Server Core installation),Windows 11 Version 23H2 for ARM64-based Systems,Windows 11 Version 23H2 for x64-based Systems,Windows Server 2022, 23H2 Edition (Server Core installation),Windows 11 Version 24H2 for ARM64-based Systems,Windows 11 Version 24H2 for x64-based Systems,Windows Server 2025,Windows 10 for 32-bit Systems,Windows 10 Version 1809 for 32-bit Systems,Windows 10 Version 1809 for x64-based Systems,Windows 10 for x64-based Systems,Windows 10 Version 1607 for 32-bit Systems,Windows 10 Version 1607 for x64-based Systems,Windows Server 2016,Windows Server 2016 (Server Core installation),Windows Server 2008 for 32-bit Systems Service Pack 2,Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation),Windows Server 2008 for x64-based Systems Service Pack 2,Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation),Windows Server 2008 R2 for x64-based Systems Service Pack 1,Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation),Windows Server 2012,Windows Server 2012 (Server Core installation),Windows Server 2012 R2,Windows Server 2012 R2 (Server Core installation),Microsoft Office for Android,Microsoft Office for Universal。
Description (English)
Microsoft Windows GDI+ is a graphic device interface for a Windows operating system of Microsoft USA. The software is part of the .NET framework and is responsible for drawing graphic images and displaying information on screens and printers. Microsoft Windows GDI+ has a security gap. The attackers used the loophole to enforce the code. The following products and versions are affected: Wows Service, Wow Service Service Service, Wow Service Service Service Service, Wow Service Service Service Service Service Service Service, Wow Service Service Service Service Service Service Service Service, W Office Service Service Service Service Service Service Service Service, W Office Service Service Service Service Service Service Service Service Service Service, W Office Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Service Office Service Service Service Service Service Service Service Service Service Service Service Service Service Service Office Service Service Service Service Service Service Service Service Service Service Service Office Office Service Service Service Service Service Service Service Service Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office Office
Hazard Level
Low
Vulnerability Type
其他
Affected Vendor
微软
Published
2025-08-12
Last Modified
2026-02-24
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53766
Patch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53766
Share on: