Information Disclosure Vulnerability in Windows Imaging Component by Microsoft
CVE-2025-53799

5.5MEDIUM

What is CVE-2025-53799?

An uninitialized resource in the Windows Imaging Component enables unauthorized attackers to access sensitive information locally, posing a risk to system integrity. This vulnerability underscores the importance of ensuring proper initialization and management of resources to prevent potential data breaches. For more information, visit the Microsoft advisory.

Affected Version(s)

Microsoft Office for Android Unknown 16.0.1 < 16.0.19220.20000

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21128

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8422

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53799 : Information Disclosure Vulnerability in Windows Imaging Component by Microsoft