Junglewise Threat Intelligence

CVE-2026-40403: Microsoft Windows Win32K heap overflow in GRFX

CVE-2026-40403 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows kernel component responsible for graphics processing. An attacker who already has basic access to a computer could exploit this flaw to gain full control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete system shutdown.

Technical details

A heap-based buffer overflow (CWE-122) exists within the Win32K - GRFX component of the Windows operating system. The vulnerability is triggered when the kernel-mode driver improperly handles memory allocation or data copying during graphics operations. An attacker with low-privileged local access can exploit this flaw without any user interaction. Successful exploitation allows the attacker to escape the user-mode sandbox and execute code with SYSTEM privileges, leading to a full compromise of the host's confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats