A vulnerability in the Windows Theme API used in Microsoft Windows could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.
The vulnerability exists because the affected software improperly performs file decompression operations. An attacker could exploit the vulnerability by persuading a user to access a link that submits malicious input to the affected software. A successful exploit could allow the attacker to execute arbitrary code and compromise the system completely.
Microsoft confirmed the vulnerability and released software updates.
Security Impact Rating: Medium