Executive brief
A stack-based buffer overflow vulnerability exists in Microsoft's Graphics Component that allows an authorized local user to execute arbitrary code and escalate their privileges. If exploited, an attacker with valid credentials could gain elevated system access, potentially compromising the confidentiality and integrity of data on affected systems.
Technical details
This vulnerability is a stack-based buffer overflow in the Microsoft Graphics Component, exploitable by an authenticated local attacker. The vulnerability allows privilege escalation through memory corruption on the stack, enabling execution of arbitrary code with elevated privileges. Attack preconditions include valid user authentication and local system access. Patches are available via Microsoft Security Updates.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed