CVE-2026-44812
Windows Graphics Component Remote Code Execution Vulnerability
Description
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
In plain language
AI Act nowCVE-2026-44812 is a Windows/Office graphics bug that can let an attacker run code on the computer, and while it needs some user involvement, Windows users should patch now because the fix is available.
CVE-2026-44812 is a local remote-code-execution flaw caused by an integer overflow in the Windows Win32K graphics component (GRFX), allowing arbitrary code execution on affected systems without authentication but requiring user interaction.
What to do now
- Check whether you run any of these on your business devices: Windows 10/11 or Windows Server (2012/2012 R2/2016/2019/2022), and also Microsoft Word/Excel/PowerPoint for Android (where applicable).
- On Windows devices, compare your Windows version/build to the fixed versions below and plan upgrades for any device that is not yet at (or above) the fixed level.
- On Android devices, update Word/Excel/PowerPoint for Android to at least version 16.0.20131.20024.
- Apply the available Microsoft update(s) for CVE-2026-44812 using the official Microsoft Update Guide, then reboot if your update process requires it.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Blame AI: Patch Tuesday Hits Record 206 CVEsen·Dark Reading· Roundup Windows rce
- Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Roundup Windows rce
- Rapid7en·Rapid7 Blog· Roundup Windows Nightmare Eclipse
- Microsoft and Adobe Patch Tuesday, June 2026 Security Update Reviewen-us·Qualys Security Blog· Roundup Microsoft Windows patch-tuesday
- Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsen-us·BleepingComputer· Patch Windows Collaborative Translation Framework (CTFMON) patch-tuesday
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsen-us·BleepingComputer· Exploited Windows Collaborative Translation Framework (CTFMON) Nightmare Eclipse
- Microsoft June 2026 Patch Tuesday - SANS Internet Storm Centeren·SANS Internet Storm Center· Exploited Microsoft Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-44812 and every CVE in our database. Create a free account — no credit card required.
Create Free Account