CyberSum logo
HomeAboutRSS
Back

CVE-2025-50165: Critical RCE Vulnerability in Windows Graphics

Cyber Security News by CyberSum.net
Published on November 21, 2025 at 09:00 AM
2 sources
Zscaler ThreatLabz discovered CVE-2025-50165, a critical remote code execution (RCE) vulnerability with a CVSS score of 9.8 affecting the Windows Graphics Component. The vulnerability, found in windowscodecs.dll, can be exploited through malicious JPEG images embedded in files like Microsoft Office documents. Users are advised to update their systems to the patched versions to mitigate the risk.

Sources

1
https://www.zscaler.com/blogs/security-research/cve-2025-50165-critical-flaw-windows-graphics-component
2
https://securityboulevard.com/2025/11/cve-2025-50165-critical-flaw-in-windows-graphics-component/

Also Read

Malicious Rust Package Targets Crypto Developers

A malicious Rust package named evm-units, authored by ablerust, was discovered by the Socket Threat Research Team. The package, disguised as an Ethereum Virtual Machine (EVM) utility, was downloaded over 7,000 times from Crates.io. It silently executes OS-specific payloads, targeting systems based on the presence of a specific antivirus software. The package was removed promptly after being reported. The incident highlights the growing trend of malware in open source ecosystems, particularly in cryptocurrency infrastructure.

By Cyber Security News by CyberSum.netDecember 4, 2025 at 09:00 AM
CyberSum logo

Stay informed about the latest cyber security developments, incidents, and research. Your trusted source for cyber security news.

Resources

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2025 CyberSum. All rights reserved.

Made withfor the security community