Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.646
EPSS Ranking 98.4%