Sep 2025: Windows Imaging Component Information Disclosure Vulnerability
CVE-2025-53799 Published on September 9, 2025
Windows Imaging Component Information Disclosure Vulnerability
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
Weakness Type
Use of Uninitialized Resource
The software uses or accesses a resource that has not been initialized. When a resource has not been properly initialized, the software may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the software.
Products Associated with CVE-2025-53799
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Office for Android:- Version 16.0.1 and below 16.0.19220.20000 is affected.
- Version 10.0.10240.0 and below 10.0.10240.21128 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.19044.0 and below 10.0.19044.6332 is affected.
- Version 10.0.19045.0 and below 10.0.19045.6332 is affected.
- Version 10.0.22621.0 and below 10.0.22621.5909 is affected.
- Version 10.0.22631.0 and below 10.0.22631.5909 is affected.
- Version 10.0.22631.0 and below 10.0.22631.5909 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27929 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27929 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23529 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23529 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25675 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25675 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22774 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22774 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.20348.0 and below 10.0.20348.4171 is affected.
- Version 10.0.25398.0 and below 10.0.25398.1849 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.