Junglewise Threat Intelligence

CVE-2026-44812: Microsoft Windows integer overflow in Win32K GRFX

CVE-2026-44812 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows graphics subsystem (Win32K), which is responsible for managing how applications display visual elements on the screen. An attacker who already has limited access to a computer could exploit this flaw to gain full control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete disruption of business operations on the affected machine.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists within the Windows Win32K - GRFX component. The flaw is triggered when the graphics engine incorrectly handles specific memory calculations, leading to a memory corruption state. An attacker can exploit this locally by running a specially crafted application, though user interaction is required (UI:R). Successful exploitation allows the attacker to escape low-privilege environments and execute arbitrary code with system-level permissions. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Windows Win32K - GRFX

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References