Junglewise Threat Intelligence

CVE-2026-25180: Microsoft Graphics Component out-of-bounds read

CVE-2026-25180 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Microsoft Office, Microsoft Windows 10, Microsoft Windows Server, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Graphics Component could allow an attacker to access sensitive information on an affected system. To exploit this, an attacker would typically need to convince a user to open a specially crafted file or run a malicious application locally. While it does not allow for direct control of the system, the leaked information could be used to facilitate further, more complex attacks.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists within the Microsoft Graphics Component across multiple versions of Windows, Windows Server, and Microsoft Office for Android. The flaw is triggered when the component improperly handles memory during the processing of specifically crafted graphical content. An attacker with local access can exploit this by inducing a user to interact with a malicious file or application, leading to the disclosure of sensitive information from the process memory. This information disclosure could potentially be used to bypass security mitigations like ASLR. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019
  • Microsoft Office Android versions prior to 16.0.19822.20000

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory

References

Related threats