Executive brief
Windows GDI+ is a graphics rendering library used by thousands of Windows applications to display images and perform drawing operations. This vulnerability allows an authenticated attacker with local access to read sensitive information from memory that should have been cleared, potentially exposing data from other applications or system processes.
Technical details
The vulnerability is a use-of-uninitialized-resource flaw in the Windows GDI+ graphics library that allows unauthorized access to uninitialized memory. An authenticated attacker with local access can exploit this vulnerability to disclose sensitive information from memory regions that were not properly cleared. The attack requires local authentication and user-level privileges. Successful exploitation results in information disclosure from the GDI+ rendering pipeline. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Windows GDI+
Timeline
- 2026-09-08: disclosed