Vulnerability · NVD
CVE-2025-53799
CVE-2025-53799, rated critical by the vendor: 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 5.5
- Exploitation
- 0.8 %
- Tracked apps
- 1
- Still exposed
- 0
Base CVSS ; severity is a vendor rating (different scale)
EPSS, predicted over 30 days
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
NVD references 16 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2025 Fixed in 10.0.26100.6584
- Windows Server 2022 (Server Core installation) Fixed in 10.0.20348.4171
- Windows Server 2022 Fixed in 10.0.25398.1849
- Windows Server 2019 Fixed in 10.0.17763.7792
- Windows Server 2016 Fixed in 10.0.14393.8422
- Windows 11 24H2 · 2024-H2 Fixed in 10.0.26100.6584
- Windows 11 23H2 · 2023-H2 Fixed in 10.0.22631.5909
- Windows 11 22H2 · 2022-H2 Fixed in 10.0.22621.5909
- Windows 10 22H2 · 2022-H2 Fixed in 10.0.19045.6332
- Windows 10 21H2 · 2021-H2 Fixed in 10.0.19044.6332
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.7792
- Windows 10 1607 · 2016-07 Fixed in 10.0.14393.8422
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| microsoft |
office Android
|
Android | <16.0.19220.20000 | cpe:2.3:a:microsoft:office:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.