Impact
An integer overflow or wraparound bug exists in the Windows Win32K Graphics (GRFX) subsystem, allowing an unauthorized local attacker to manipulate memory boundaries and execute arbitrary code on the affected system. The flaw stems from improper handling of numeric values, enabling the attacker to overflow counters or pointers used by the graphics driver.
Affected Systems
The vulnerability impacts Microsoft Excel for Android, PowerPoint for Android, and Word for Android; Windows 10 1607, 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. All listed OS and Office for Android versions are affected.
Risk and Exploitability
The CVSS score of 7.8 highlights a high severity level. EPSS is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The likely attack vector is local code execution, requiring the attacker to be able to run code with sufficient privileges to trigger the overflow. No remote exploitation path is described in the current data.
OpenCVE Enrichment