Executive brief
A security vulnerability exists in the Windows component responsible for processing graphics and images. This flaw could allow an attacker who already has access to a computer to run malicious software with elevated permissions. If exploited, this could lead to a full system takeover, unauthorized data access, or disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows GDI+ (Graphics Device Interface Plus) component. The vulnerability is triggered when the system improperly handles objects in memory during graphics rendering. An attacker with local access can exploit this to execute arbitrary code with the privileges of the logged-on user or the system. The attack vector is local, and according to the CVSS metrics, it requires no prior privileges or user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft
- 2026-07-14: advisory: NVD record published