Junglewise Threat Intelligence

CVE-2026-54987: Microsoft Windows heap overflow in Windows Overlay Filter

CVE-2026-54987 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012 R2, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Overlay Filter, a component of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows Overlay Filter component. The vulnerability is triggered locally by an authenticated user with low privileges (PR:L). By exploiting this memory corruption issue, an attacker can execute arbitrary code with elevated system privileges. The attack does not require user interaction and has a high impact on confidentiality, integrity, and availability. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 R2 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record by Microsoft.
  • 2026-07-14: advisory: NVD entry published.

References

Related threats