Executive brief
A vulnerability in the Microsoft Graphics Component, which handles visual rendering and image processing in Windows, could allow an attacker to run malicious code on a target system. While the attacker must already have local access to the machine, successful exploitation could lead to a full system compromise, data theft, or permanent damage to the operating system. This affects modern versions of Windows 11 and Windows Server 2025.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Microsoft Graphics Component. The vulnerability is triggered when the component improperly handles memory allocation during graphics processing, allowing an attacker to overwrite adjacent memory. Although the attack vector is local (AV:L), it requires no special privileges (PR:N) or user interaction (UI:N). Successful exploitation enables arbitrary code execution with the privileges of the affected process, potentially leading to a full compromise of the host's confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows 11 and Windows Server 2025 builds.
Affected products
- Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.8246
- Microsoft Windows 11 Version 25H2 up to (excluding) 10.0.26200.8246
- Microsoft Windows 11 version 26H1 up to (excluding) 10.0.28000.1836
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32690
Timeline
- 2026-04-14: disclosed: Initial publication by Microsoft
- 2026-04-14: advisory: MSRC advisory published