Executive brief
A critical vulnerability exists in Windows GDI+, a core component used by Windows to display graphics and formatted text. An attacker could exploit this flaw to take complete control of a computer if a user views a specially crafted image or website. This could lead to the theft of sensitive data, installation of malware, or a total disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows GDI+ component. The vulnerability is triggered when the system improperly handles specially crafted graphic data, leading to memory corruption. An unauthenticated attacker can exploit this over the network, though it requires user interaction (UI:R), such as visiting a malicious website or opening a rigged file. Successful exploitation allows for remote code execution (RCE) with the privileges of the logged-in user. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory