SB2025090966 - Multiple vulnerabilities in Microsoft Windows Graphics Component
Published: September 9, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Incorrect Initialization of Resource (CVE-ID: CVE-2025-53800)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect initialization of resource in Windows Graphics Component, which leads to security restrictions bypass and privilege escalation.
2) Race condition (CVE-ID: CVE-2025-55228)
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a race condition in Windows Graphics Component. A remote user can run a specially crafted application to exploit the race and execute arbitrary code on the target system.
3) Race condition (CVE-ID: CVE-2025-53807)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in Windows Graphics Component. A local user can exploit the race and escalate privileges on the system.
4) Race condition (CVE-ID: CVE-2025-54919)
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a race condition in Windows Graphics Component. A remote user can exploit the race and execute arbitrary code on the target system.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-53800
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-55228
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-53807
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-54919