Junglewise Threat Intelligence

CVE-2026-20822: Microsoft Windows Graphics Component use after free privilege escalation

CVE-2026-20822 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Graphics Component, a core part of the Windows operating system responsible for displaying visual content. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Microsoft Graphics Component of Windows and Windows Server. The flaw is triggered when the system incorrectly handles objects in memory, allowing a locally authenticated attacker with low privileges to execute code with elevated system permissions. While the attack requires local access and involves high complexity (AC:H), successful exploitation results in a scope change (S:C), granting the attacker full control over the affected host. Microsoft has released security updates to address this issue across supported versions of Windows 10, 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2016 All versions including Server Core

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched

References

Related threats