Impact
Microsoft Graphics Component contains a stack-based buffer overflow that can be triggered by an attacker with authorized access on the affected system. The overflow corrupts execution context and permits the attacker to gain higher privileges locally, effectively enabling local privilege escalation. This vulnerability is a classic instance of CWE-121, where unchecked memory writes lead to escalated execution rights.
Affected Systems
Affected systems include Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (both full and Server Core editions). The vulnerability impacts both ARM64 and x64 architectures in Windows 11, and all supported architectures in Windows Server.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity risk. Without an EPSS score available, the exact likelihood of exploitation is unknown; however, the vulnerability is not currently listed in the CISA KEV catalog. Attack requires that the attacker already has local access to the machine, making it a local privilege escalation vector. Exploitation would likely involve the attacker running a specially crafted payload, possibly through a compromised application utilizing the graphics component.
OpenCVE Enrichment