CVE-2025-50165: Windows Graphics Component Remote Code Execution Vulnerability
Published Aug 12, 2025
·Updated
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Other sources
Windows Graphics Component Remote Code Execution Vulnerability
— Microsoft
Affected Software
6 affected componentsFixes available
Microsoft Windows 11=24H2
Microsoft Windows Server 2025
Microsoft Windows Server 2025
Microsoft Windows 11=24H2
Microsoft Windows 11 24h2<10.0.26100.4851
Microsoft Windows Server 2025<10.0.26100.4851
Event History
Aug 14, 2024
News Published
12:45 AM
Aug 12, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via The Register·11:34 PM
News Published
via The Register·11:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-50165?
CVE-2025-50165 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2025-50165?
To fix CVE-2025-50165, ensure that you install the latest patches provided by Microsoft for affected versions.
3
Which versions of Microsoft products are affected by CVE-2025-50165?
CVE-2025-50165 affects Microsoft Windows 11 version 24H2 and Microsoft Windows Server 2025.
4
Can CVE-2025-50165 be exploited remotely?
Yes, CVE-2025-50165 can be exploited remotely, allowing unauthorized attackers to execute code over a network.
5
What type of vulnerability is CVE-2025-50165?
CVE-2025-50165 is classified as an untrusted pointer dereference vulnerability in the Microsoft Graphics Component.