Junglewise Threat Intelligence

CVE-2026-40377: Microsoft Windows heap overflow in Cryptographic Services

CVE-2026-40377 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Windows Cryptographic Services, the component responsible for managing digital certificates and encryption tasks. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or the complete disruption of business operations on the affected machine.

Technical details

A heap-based buffer overflow (CWE-122) exists within the Microsoft Windows Cryptographic Services component. The vulnerability is triggered when the service improperly handles memory allocation during cryptographic operations. An attacker with low-privileged local access can exploit this flaw by sending specially crafted requests to the service, leading to memory corruption. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue via the MSRC Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-05-12: advisory: NVD record published

References

Related threats