Stack-Based Buffer Overflow in Windows GDI Affecting Microsoft Products
CVE-2026-50387

7.8HIGH

What is CVE-2026-50387?

A stack-based buffer overflow vulnerability exists in Windows Graphics Device Interface (GDI), which allows a local attacker with valid credentials to execute arbitrary code with elevated privileges. This could lead to increased access levels, allowing attackers to perform unauthorized actions within the system.

Affected Version(s)

Microsoft Office 365 for Mac 1.0.0 < 16.111.26071215

Microsoft Office for Android 16.0.1 < 16.0.20228.20042

Microsoft Office LTSC for Mac 2021 16.0.1 < 16.111.26071215

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.