Description
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow in the Windows GDI subsystem allows a local attacker with authorized access to escape the current privilege level and execute code with elevated rights, resulting in local privilege escalation. The flaw is a classic stack corruption that exposes the system to arbitrary memory write, and is identified as CWE‑121. According to the CVE description, the vulnerability can compromise system integrity and may allow the attacker to perform operations normally restricted to administrators.

Affected Systems

Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012 through 2025, including Server Core editions; and Microsoft Office products such as Office 365 for Mac, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Office for Android.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score of <1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, meaning no confirmed public exploits yet. Because the flaw requires local authorization, the attack surface is limited to systems with legitimate user logins, but the elevated privileges that can be gained present a significant risk if the attacker can access the target machine.

Generated by OpenCVE AI on August 24, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security updates for the affected Windows operating systems and Microsoft Office products that address CVE-2026-50387.
  • Reboot all impacted systems after applying the updates to ensure the changes take effect and replace the old GDI binaries.
  • If the update cannot be applied immediately, isolate vulnerable systems from external connections and restrict local user privileges to reduce the window of opportunity for exploitation.

Generated by OpenCVE AI on August 24, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
Title Windows GDI Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft office
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-121
CPEs cpe:2.3:a:microsoft:office:*:*:android:*:*:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft office
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Copilot Microsoft 365 Office Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 21h2 Windows 10 22h2 Windows 10 22h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:37:53.956Z

Reserved: 2026-06-04T18:55:14.745Z

Link: CVE-2026-50387

cve-icon Vulnrichment

Updated: 2026-07-15T13:34:07.898Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-14T18:17:40.390

Modified: 2026-07-22T16:17:49.360

Link: CVE-2026-50387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:30:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow