ZeroHour

CVE-2025-5473

mass

Integer Overflow Leading to RCE in GIMP ICO File Parsing

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2025-5473 is an integer overflow (CWE-190) in the way GIMP parses ICO (icon) files, caused by insufficient validation of user-supplied data before writing to memory. It is triggered when a user opens a malicious ICO file or visits a malicious page that leads GIMP to process a crafted file, so user interaction is required. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current GIMP process, generally with the privileges of the logged-in user. Anyone running an affected GIMP installation that opens untrusted image files is at risk; the source data does not specify exact affected version ranges. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but EPSS assigns a 23.5% probability of exploitation within 30 days (98th percentile), and the issue was reported through the Zero Day Initiative (ZDI-CAN-26752).

What to do: Upgrade GIMP to the latest vendor release containing the ICO parser fix as soon as it is published, and check GIMP's official release notes or the ZDI advisory for the specific fixed version. Until systems are patched, do not open ICO files or untrusted images from email, downloads, or web sources with GIMP. Given the elevated EPSS score, monitor CISA KEV and vendor advisories for confirmation of active exploitation.

Affected
GIMP (GNU Image Manipulation Program)
Estimated exposure
massmillions of desktop installations worldwide (GIMP has tens of millions of cumulative downloads as a leading free image editor) — GIMP is a free, widely deployed open-source image editor on Windows/macOS/Linux with very large cumulative download counts and no fixed active-install telemetry, so a multi-million installed base is the best order-of-magnitude estimate,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.

Vendors
gimp
Products
gimp
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.