Impact
A null pointer dereference in the Microsoft Graphics Component can be triggered by an unauthorized local attacker, causing the graphics stack to crash and effectively denying service on the affected system. This flaw maps to CWE‑476 and can lead to the system becoming unresponsive without needing elevated privileges. The disruption is confined to the local machine, but can impact critical applications that rely on graphics rendering.
Affected Systems
The flaw affects a wide range of Windows releases, including Windows 10 starting with version 1607, Windows 10 through 22H2, Windows 11 from 23H2 through 26H1, as well as Windows Server 2012 through 2025, including all core and standard installations.
Risk and Exploitability
The CVSS score is 6.2, indicating moderate severity. The EPSS score is below 1%, suggesting a low likelihood of current exploitation, and the vulnerability has not been listed in the CISA KEV catalog. Exploitation would require a local attacker with the ability to execute code that can reach the problematic component, so while it can disrupt services, it does not permit remote code execution or privilege escalation.
OpenCVE Enrichment