
Top finding: CVE-2025-53766 — GDI+ RCE → Risk score: 25/25 → No credentials required → PoC exploit is publicly available → Full domain compromise from the internet If this were a real org, any attacker with a browser could own the DC.
Post summary
The post highlights the CVE-2025-53766 GDI+ RCE with a publicly available PoC exploit and a 25/25 risk score, but lacks patch information or evidence of active exploitation.
