Description
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Windows Graphics Component permits an attacker who is already logged into the system to read sensitive data that should not be exposed. This results in local information disclosure. The vulnerability is classified with CWE‑200, indicating it is an information disclosure weakness. As the CVE description states that the disclosure can be triggered by an authorized attacker, it is inferred that the attacker must have local user credentials to exercise this vulnerability.

Affected Systems

Affected systems include Microsoft Windows 11 releases 24H2, 25H2, 26H1 and Windows Server 2025, including Server Core installations. The flaw resides in the graphics runtime component present in these operating system builds.

Risk and Exploitability

The CVSS base score of 5.5 indicates a medium severity issue, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, further implying limited observed exploitation. It is inferred that the attack vector is local authentication, meaning that threat actors must already have legitimate access to the machine to extract data. Although a single compromised account can leak valuable information that may aid further attacks, the overall attack surface remains confined to authorized users.

Generated by OpenCVE AI on July 31, 2026 at 07:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update for Windows 11 and Windows Server 2025 that fixes the Windows Graphics Component disclosure.
  • If an immediate update is not possible, restrict local user privileges that grant access to graphics APIs or disable unnecessary graphics services where feasible.
  • Monitor system logs for suspicious access to graphics components and investigate any anomalies promptly.

Generated by OpenCVE AI on July 31, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
Title Windows Graphics Component Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-200
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:19.000Z

Reserved: 2026-06-04T18:59:53.336Z

Link: CVE-2026-50483

cve-icon Vulnrichment

Updated: 2026-07-15T13:27:42.585Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:45:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor