CVE-2026-21246

high Microsoft
CVSS v3 Base Score
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Published: February 10, 2026
Last Modified: March 13, 2026
Vendor: Microsoft
Source: MITRE

Description

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CWE

CWE-122

Affected Products

Microsoft Windows 10 Version 1607Microsoft Windows 10 Version 1809Microsoft Windows 10 Version 21H2Microsoft Windows 10 Version 22H2Microsoft Windows 11 version 22H3Microsoft Windows 11 Version 23H2Microsoft Windows 11 Version 24H2Microsoft Windows 11 Version 25H2Microsoft Windows Server 2012Microsoft Windows Server 2012 (Server Core installation)

References