Integer Overflow Vulnerability in Windows Win32K Graphics Component
CVE-2026-44803

7.8HIGH

What is CVE-2026-44803?

CVE-2026-44803 is a significant vulnerability affecting the Windows Win32K graphics component developed by Microsoft. This flaw arises from an integer overflow issue that can be exploited by unauthorized attackers to execute code locally on affected systems. The vulnerability primarily threatens environments that utilize Windows for graphics processing, potentially compromising the integrity of various applications and services reliant on the Win32K subsystem. If leveraged, this vulnerability can lead to unauthorized access and manipulation of system resources, posing risks to sensitive data and operational stability in organizations that depend on Windows-based infrastructures.

Potential impact of CVE-2026-44803

  1. Unauthorized Code Execution: Attackers can exploit this vulnerability to execute arbitrary code on systems running vulnerable versions of Windows, leading to unauthorized access and control over the system.

  2. Compromise of System Integrity: The ability to execute code locally can allow adversaries to manipulate system functionalities, potentially resulting in data corruption or unauthorized modifications to critical processes.

  3. Increased Attack Surface: As this vulnerability is tied to a core component of the operating system, its exploitation can open pathways for further attacks, enabling the installation of malware or the facilitation of additional exploitation techniques within the network, significantly enhancing the risk of broader breaches.

Affected Version(s)

Microsoft Excel for Android 16.0.0.0 < 16.0.20131.20024

Microsoft PowerPoint for Android 16.0.0.0 < 16.0.20131.20024

Microsoft Word for Android 16.0.0.0 < 16.0.20131.20024

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.