CVE-2025-62821

🔴 Łataj teraz

Błąd odczytu poza granicami w Microsoft HEIF Image Extensions umożliwia potencjalne wycieki danych.

CVSS
9.1
EPSS
1.1%
Exploit
poc
Vendor
microsoft
Opis źródłowy (NVD)

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.1%
Opublikowano (NVD)2026-06-19 14:16:21 UTC
Ostatnia modyfikacja (NVD)2026-10-05 18:10:00 UTC
Referencje