Junglewise Threat Intelligence

CVE-2026-49796: Microsoft Windows GDI+ heap overflow

CVE-2026-49796 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Windows GDI+, a core component used by the operating system to display graphics and formatted text. An attacker could exploit this flaw to run malicious code on a user's computer, potentially leading to a full system takeover or data theft. To carry out the attack, a user would typically need to be tricked into opening a specially crafted file or visiting a malicious website.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows GDI+ component. The vulnerability is triggered when the system improperly handles specially crafted graphics data, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file or interact with a malicious application, resulting in local code execution with the privileges of the logged-in user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions including Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security update guide details.

References

Related threats