CVE-2026-40403: Windows Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
Other sources
Windows Graphics Component Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8457Fixed in 10.0.26200.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7291Patch KB5087544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9140Patch KB5087537 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23181Patch KB5087471 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26079Patch KB5087470 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2113Patch KB5089548 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8457Fixed in 10.0.26100.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7079Patch KB5087420
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and able to execute code locally. The provided data does not indicate a remote or unauthenticated exploitation path.
Which systems should be prioritized for remediation?
Systems running the listed Microsoft Windows client or server products should be assessed, particularly where low-privileged users, shared access, or untrusted local workloads are permitted. Successful exploitation can result in high confidentiality, integrity, and availability impact.
What is the likely security impact after exploitation?
The vulnerability is a heap-based buffer overflow in Win32K - GRFX that allows local code execution by an authorized attacker. Its scope is changed and the supplied vector rates confidentiality, integrity, and availability impacts as high.