Junglewise Threat Intelligence

CVE-2026-58609: Microsoft Graphics Component out-of-bounds read code execution

CVE-2026-58609 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows Server 2012. Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Graphics Component could allow an attacker to execute malicious code on a target computer. This component is responsible for how Windows displays images and visual elements. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file or visiting a malicious website, potentially leading to a full system compromise or data theft.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within the Microsoft Graphics Component. The flaw is triggered when the component improperly handles memory while processing specially crafted graphical content. An attacker can exploit this by convincing a user to open a malicious file or interact with a malicious application (User Interaction required). Successful exploitation allows for local code execution with the privileges of the logged-in user. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References