SB2025090966 - Multiple vulnerabilities in Microsoft Windows Graphics Component



SB2025090966 - Multiple vulnerabilities in Microsoft Windows Graphics Component

Published: September 9, 2025

Security Bulletin ID SB2025090966
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Incorrect Initialization of Resource (CVE-ID: CVE-2025-53800)

CWE-ID: CWE-1419 - Incorrect Initialization of Resource

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect initialization of resource in Windows Graphics Component, which leads to security restrictions bypass and privilege escalation.


2) Race condition (CVE-ID: CVE-2025-55228)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to a race condition in Windows Graphics Component. A remote user can run a specially crafted application to exploit the race and execute arbitrary code on the target system.


3) Race condition (CVE-ID: CVE-2025-53807)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in Windows Graphics Component. A local user can exploit the race and escalate privileges on the system.


4) Race condition (CVE-ID: CVE-2025-54919)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to a race condition in Windows Graphics Component. A remote user can exploit the race and execute arbitrary code on the target system.


Remediation

Install update from vendor's website.