Buffer Over-read Vulnerability in Windows GDI+ by Microsoft
CVE-2026-20846
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-20846?
The vulnerability in Windows GDI+ pertains to a buffer over-read issue that could allow an unauthorized attacker to disrupt service over a network. This flaw poses significant risks by potentially enabling denial of service attacks, affecting the stability and availability of the system.
Affected Version(s)
Microsoft Office for Android 16.0.1 < 16.0.19822.20000
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8868
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8389