Critical Windows Imaging Component Flaw CVE-2025-50165 Exploits JPG Files

Critical Windows Imaging Component Flaw CVE-2025-50165 Exploits JPG Files

First seen 23 Dec 2025, 17:01 UTC WelivesecurityEset 91% similarity 40.2

Article Content

Browse articles
ThreatCluster

ESET researchers analyzed CVE-2025-50165, a serious vulnerability in the Windows Imaging Component that allows remote code execution through specially crafted JPG files. The flaw was identified by Zscaler ThreatLabz, and while Microsoft rated its severity as critical, they assessed that the exploitability is less likely. ESET's analysis pinpointed the faulty code and reproduced the crash.

ThreatCluster AI

Community

Browse all →