Executive brief
A security vulnerability has been identified in the Windows Graphics Device Interface (GDI), a core component responsible for representing graphical objects and transmitting them to output devices like monitors and printers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view or delete sensitive data, install malicious software, or disrupt business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Windows Graphics Device Interface (GDI) component. The vulnerability is triggered when the component improperly handles specific graphical objects or data structures in memory. An attacker with low-privileged local access can exploit this flaw by running a specially crafted application to overwrite stack memory, leading to arbitrary code execution with elevated privileges (typically SYSTEM). The vulnerability affects multiple versions of Windows 10, Windows 11, and Microsoft Office suites on Mac and Android. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2
- Microsoft Microsoft Office for Mac 365, LTSC 2021, LTSC 2024 (versions < 16.111.26071215)
- Microsoft Microsoft Office for Android < 16.0.20228.20042
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory