CVE-2023-28291: Microsoft Raw Image Extension

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Raw Image Extension Remote Code Execution Vulnerability

Affected products

  • Microsoft Raw Image Extension: before 2.1.60611.0 (fixed in 2.1.60611.0); before 2.0.60612.0 (fixed in 2.0.60612.0)

Published 2023-04-11. Last modified 2026-06-17.