Moneycontrol PRO
HomeTechnologyMicrosoft Windows 11, Windows 10 and Microsoft Office are affected by a new graphics-component security flaw; government issues warning

Microsoft Windows 11, Windows 10 and Microsoft Office are affected by a new graphics-component security flaw; government issues warning

A new CERT-In advisory warns of a remote code execution flaw in Microsoft’s graphics component affecting multiple Windows and Office versions, enabling attackers to run malicious code through crafted metafiles.

November 17, 2025 / 17:37 IST
Windows warning

India’s Computer Emergency Response Team (CERT-In) has issued a high-severity alert for a remote code execution vulnerability affecting Microsoft Graphics Components (GDI+). The flaw, tracked as CVE-2025-60724, impacts a wide range of Windows versions, including Windows 10, Windows 11, Windows Server editions from 2008 to 2025, and Microsoft Office on Mac and Android. The agency warns that the vulnerability could allow attackers to execute arbitrary code or access sensitive information on targeted systems.

Affected platforms
According to the advisory, the vulnerability spans several generations of Windows, beginning with Windows Server 2008 and extending to the latest Windows 11 and Server 2025 builds. Both 32-bit and 64-bit systems are affected. Microsoft Office LTSC for Mac (2021 and 2024) and Microsoft Office for Android are also listed as impacted products.
CERT-In notes that all end-user organisations and individuals using Microsoft’s graphics rendering components may be exposed to the risk.

Nature of the vulnerability
CERT-In explains that the flaw stems from a heap-based buffer overflow in Microsoft Graphics Components. An attacker can exploit the issue by persuading a user to download and open a document containing a specially crafted metafile. When processed, the malicious file could trigger the overflow and enable remote execution of harmful code.
Successful exploitation may lead to unauthorised access, potential data exposure or complete compromise of the affected system. The agency classifies the risk level as high, urging immediate attention from organisations and users.

Security impact and risks
The primary impact is remote code execution, which could allow attackers to take control of a device, manipulate data or expand access within an organisation’s network. CERT-In highlights the possibility of information disclosure as an additional threat.
Given the widespread use of Windows graphics processing libraries across consumer and enterprise environments, the vulnerability poses a significant security concern if left unpatched.

Update and mitigation
CERT-In recommends that users and administrators apply the patches released by Microsoft. The security updates addressing CVE-2025-60724 are available through Microsoft’s update guide.
Official link: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-60724

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Nov 17, 2025 02:41 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347