CVE Tools

Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component

ESET WeLiveSecurityBy Romain Dumont8 min read

ResearchWindows Imaging Component (WindowsCodecs.dll)
Read at ESET WeLiveSecurity

Below is the opening; the full story is at ESET WeLiveSecurity.

From ESET WeLiveSecurity

ESET researchers examined CVE‑2025‑50165, a serious Windows vulnerability described to grant remote code execution by merely opening a specially crafted JPG file – one of the most widely used image formats. The flaw, found and documented by Zscaler ThreatLabz, piqued our interest, as Microsoft assessed its severity as critical but deemed its exploitability as less likely. Our root cause analysis allowed us to pinpoint the exact location of the faulty code and reproduce the crash. We believe that the exploitation scenario is harder than it appears to be.…

Continue at ESET WeLiveSecurity

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store