Severity: Critical
CVSS Score: 7.8
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.