Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
Microsoft Graphics Component Can Leverage Local Data Exposure
CVE-2026-25180
Summary
A vulnerability in the Microsoft Graphics Component could allow an attacker with local access to access sensitive information they shouldn't see. This could potentially lead to unauthorized access to confidential data. Update Microsoft Graphics Component to the latest version to mitigate this risk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| microsoft | office | <= 16.0.19822.20000 | – |
| microsoft | windows_10_1607 | <= 10.0.14393.8957 | – |
| microsoft | windows_10_1607 | <= 10.0.14393.8957 | – |
| microsoft | windows_10_1809 | <= 10.0.17763.8511 | – |
| microsoft | windows_10_1809 | <= 10.0.17763.8511 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_11_23h2 | <= 10.0.22631.6783 | – |
| microsoft | windows_11_23h2 | <= 10.0.22631.6783 | – |
| microsoft | windows_11_24h2 | <= 10.0.26100.7979 | – |
| microsoft | windows_11_24h2 | <= 10.0.26100.7979 | – |
| microsoft | windows_11_25h2 | <= 10.0.26200.7979 | – |
| microsoft | windows_11_25h2 | <= 10.0.26200.7979 | – |
| microsoft | windows_11_26h1 | <= 10.0.28000.1719 | – |
| microsoft | windows_11_26h1 | <= 10.0.28000.1719 | – |
| microsoft | windows_server_2012 | All versions | – |
| microsoft | windows_server_2012 | r2 | – |
| microsoft | windows_server_2016 | <= 10.0.14393.8957 | – |
| microsoft | windows_server_2019 | <= 10.0.17763.8511 | – |
| microsoft | windows_server_2022 | <= 10.0.20348.4830 | – |
| microsoft | windows_server_2022_23h2 | <= 10.0.25398.2207 | – |
| microsoft | windows_server_2025 | <= 10.0.26100.32463 | – |
Original title
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
Original description
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
nvd CVSS3.1
5.5
Vulnerability type
CWE-125
Out-of-bounds Read
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026