PT-2026-40182 · Microsoft · Windows

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-35421

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description A heap-based buffer overflow in the Windows GDI (Graphics Device Interface), which is the graphics subsystem of Windows, allows an unauthorized attacker to execute arbitrary code. This issue can be exploited both locally and remotely to affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-35421

Affected Products

Windows