Executive brief
Windows GDI is a core graphics component responsible for rendering text, images, and visual elements across the operating system. An authorized attacker can exploit an out-of-bounds read vulnerability to access sensitive information stored in system memory, potentially exposing confidential data or enabling further attacks.
Technical details
The vulnerability is an out-of-bounds read in the Windows Graphics Device Interface (GDI), allowing an authenticated attacker to read beyond allocated memory boundaries. The attack requires local access and user authentication, limiting exposure to insider threats or compromised accounts. An attacker can exploit this flaw to disclose sensitive information from kernel or application memory. The vulnerability has been assigned CVE-2026-65662 with a CVSS score of 5.5 (medium severity) and there is no evidence of active exploitation in the wild at this time.
Affected products
- Microsoft Windows
Timeline
- 2026-08-11: disclosed