Junglewise Threat Intelligence

CVE-2026-35421: Microsoft Windows heap overflow in GDI

CVE-2026-35421 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Graphics Device Interface (GDI), a core component responsible for representing graphical objects and transmitting them to output devices like monitors and printers. An attacker could exploit this flaw to run malicious code on a user's computer, potentially leading to a full system takeover or data theft. To be successful, the attack requires a user to open a specially crafted file or visit a malicious website.

Technical details

A heap-based buffer overflow (CWE-122) exists within the Microsoft Windows Graphics Device Interface (GDI). The vulnerability is triggered when the GDI component improperly handles specially crafted graphical content, leading to memory corruption. While the attack vector is local, it requires user interaction (UI:R), typically involving a user opening a malicious file or document that renders via GDI. Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the logged-in user, potentially leading to a complete compromise of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats