Executive brief
Microsoft's UxTheme Library (uxtheme.dll) is a core Windows component that manages visual themes and user interface styling. An integer underflow vulnerability in this library allows attackers to execute malicious code remotely over a network, potentially compromising system security and user data without requiring user interaction.
Technical details
The vulnerability is an integer underflow (wrap or wraparound) flaw in the Microsoft UxTheme Library (uxtheme.dll). The flaw can be exploited over a network by an unauthorized attacker to achieve remote code execution. The vulnerability requires network reachability to the affected system and does not require user interaction or authentication. An attacker can craft specially formed network packets or requests that trigger the integer underflow condition, leading to memory corruption and arbitrary code execution with the privileges of the process using the library.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed