CVE-2026-27931Out-of-bounds Read in Microsoft Windows 10 Version 21h2

CWE-125Out-of-bounds Read3 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14

Description

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.5020
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.32690
CVEListV5microsoft/windows_10_version_21h210.0.19044.010.0.19044.7184
CVEListV5microsoft/windows_10_version_22h210.0.19045.010.0.19045.7184
CVEListV5microsoft/windows_11_version_22h310.0.22631.010.0.22631.6936

🔴Vulnerability Details

2
CVEList
Windows GDI Information Disclosure Vulnerability2026-04-14
GHSA
GHSA-7jv6-2jq8-rjx4: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally2026-04-14
CVE-2026-27931 — Out-of-bounds Read in Microsoft | cvebase