Information Disclosure Vulnerability in Windows Imaging Component by Microsoft
CVE-2025-53799
5.5MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-53799?
An uninitialized resource in the Windows Imaging Component enables unauthorized attackers to access sensitive information locally, posing a risk to system integrity. This vulnerability underscores the importance of ensuring proper initialization and management of resources to prevent potential data breaches. For more information, visit the Microsoft advisory.
Affected Version(s)
Microsoft Office for Android Unknown 16.0.1 < 16.0.19220.20000
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21128
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8422
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved