Junglewise Threat Intelligence

CVE-2026-45606: Microsoft UxTheme Library out-of-bounds read in uxtheme.dll

CVE-2026-45606 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Microsoft UxTheme Library, which is responsible for managing the visual appearance and themes of the Windows user interface. An attacker with existing access to a computer could exploit this flaw to cause a system crash or freeze, leading to a denial of service. This would disrupt operations and require a system restart to restore functionality.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within the Microsoft UxTheme Library (uxtheme.dll). The flaw is triggered when the library improperly handles memory access during theme processing. An attacker with low-privileged local access can exploit this by running a specially crafted application, leading to a crash of the affected service or the entire operating system (Denial of Service). The attack vector is local, requiring no user interaction, but does require the attacker to have prior authentication on the target system. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Published by Microsoft and NVD

References