Executive brief
A security vulnerability has been identified in Microsoft Windows DirectX, a collection of components used for handling multimedia and graphics tasks. An attacker who already has basic access to a system could exploit this flaw to gain higher-level permissions and execute malicious code. This could lead to a full compromise of the affected computer, allowing the attacker to access sensitive data or disrupt operations.
Technical details
A vulnerability classified as an untrusted pointer dereference (CWE-822) exists within the Microsoft Windows DirectX component. The flaw allows a locally authenticated attacker with low privileges to execute arbitrary code with elevated permissions. The vulnerability is characterized by a Scope change (S:C) in the CVSS vector, indicating the attacker may be able to impact components outside of the DirectX environment. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory