Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.