Junglewise Threat Intelligence

CVE-2026-42986: Microsoft Graphics Component use after free privilege escalation

CVE-2026-42986 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Graphics Component, which handles visual rendering and display tasks for the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.

Technical details

A use-after-free vulnerability (CWE-416) exists within the Microsoft Graphics Component due to improper memory management during object lifecycle handling. An attacker with local access and low-privileged user rights can exploit this flaw by executing a specially crafted application to trigger the memory corruption. Successful exploitation allows the attacker to execute arbitrary code in the context of the SYSTEM account, leading to a full local privilege escalation (LPE). The vulnerability is reachable without user interaction, though it requires prior authentication to the target host.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References