Executive brief
A security vulnerability has been identified in Microsoft Windows DirectX, a component responsible for handling multimedia and graphics tasks. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level system permissions. This could allow them to bypass security restrictions, modify system files, or disrupt operations on the affected device.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows DirectX component. The flaw is triggered when the system improperly handles memory during graphics processing. An attacker with low-privileged local access can exploit this by running a specially crafted application to overwrite heap memory, potentially leading to local privilege escalation (LPE). While the attack requires local access and has high complexity, successful exploitation allows the attacker to gain elevated system integrity. Microsoft has released security updates to address this issue across various versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft