Untrusted Search Path Vulnerability in Windows GDI by Microsoft
CVE-2026-25190
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-25190?
The vulnerability in Windows GDI arises from an untrusted search path issue, enabling unauthorized attackers to execute arbitrary code locally. This can result in serious implications for system integrity and data security, as attackers can leverage this flaw for malicious purposes. Users should remain vigilant and apply security updates promptly to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8957
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8511
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7058
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved