FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user would need to be tricked into opening a folder that contains a specially crafted file.
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.