Junglewise Threat Intelligence

CVE-2026-77491: Microsoft Windows GDI out-of-bounds read information disclosure

CVE-2026-77491 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Windows GDI (Graphics Device Interface) is a core system component responsible for rendering graphics on Windows systems. An out-of-bounds memory read vulnerability allows a local attacker to access sensitive system information that should not be accessible, potentially exposing data such as memory contents containing user passwords or system tokens.

Technical details

This is an out-of-bounds read vulnerability in the Windows GDI subsystem. The vulnerability allows local attackers to read memory beyond allocated buffer boundaries, enabling unauthorized information disclosure. The attack requires local access to the target system; remote exploitation is not possible. The vulnerability does not allow code execution but can leak sensitive information from kernel or process memory. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats