Executive brief
A vulnerability in the Microsoft Graphics Component could allow an attacker to execute malicious code on a target computer. This component is responsible for how Windows displays images and visual elements. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file or visiting a malicious website, potentially leading to a full system compromise or data theft.
Technical details
This vulnerability is classified as an out-of-bounds read (CWE-125) within the Microsoft Graphics Component. The flaw is triggered when the component improperly handles memory while processing specially crafted graphical content. An attacker can exploit this by convincing a user to open a malicious file or interact with a malicious application (User Interaction required). Successful exploitation allows for local code execution with the privileges of the logged-in user. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide