Executive brief
A security vulnerability exists in the Microsoft Graphics Component, a core part of the Windows operating system responsible for rendering visual content. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that they should not be able to see. While this does not allow for direct control of the system, it could lead to the theft of confidential data or help facilitate further attacks.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Microsoft Graphics Component across multiple versions of Windows 11 and Windows Server 2025. The vulnerability allows a locally authenticated attacker with low privileges to gain unauthorized access to sensitive information. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system. The impact is limited to confidentiality, with no direct impact on system integrity or availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory