Executive brief
Microsoft's Graphics Component contains a double free memory vulnerability that could allow a remote attacker to execute arbitrary code on affected systems without authentication. This represents a significant risk to organizations relying on Windows systems, as successful exploitation could lead to complete system compromise, data theft, and lateral movement within corporate networks.
Technical details
The vulnerability is a double free condition in the Microsoft Graphics Component, which occurs when memory is freed twice, potentially leading to memory corruption and arbitrary code execution. The flaw is reachable over a network without requiring prior authentication or user interaction. An attacker can exploit this by sending specially crafted network packets to trigger the double free condition, gaining code execution in the context of the Graphics Component process. The high CVSS score of 9.8 reflects the ease of exploitation and severity of impact.
Affected products
- Microsoft Graphics Component
Timeline
- 2026-09-08: disclosed