Heap-Based Buffer Overflow in Windows Cryptographic Services by Microsoft
CVE-2026-40377
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40377?
The vulnerability exists due to a heap-based buffer overflow in Microsoft Windows Cryptographic Services. This flaw allows an authorized attacker with local access to the system to exploit this vulnerability, potentially enabling them to elevate their privileges and gain unauthorized access to system resources. Immediate action is recommended to mitigate the risks associated with this security issue, as it could lead to significant security breaches.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291