CVE-2026-61360
Windows GDI Information Disclosure Vulnerability
Description
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
In plain language
AI Act nowCVE-2026-61360 is a Windows problem where a low-privileged user can cause the system to reveal sensitive data from its own memory; typical small businesses should treat it as urgent if they have untrusted or loosely managed user accounts on affected Windows systems.
CVE-2026-61360 is a local, authenticated Windows GDI information disclosure (CWE-822) where a flaw in how Windows processes graphics data pointers lets an attacker read confidential operating system memory content without needing code execution.
What to do now
- Check which Windows versions you run (Windows 10, Windows 11, and Windows Server 2012/2012 R2/2016/2019/2022/2025) and whether you have any users or accounts that should not be fully trusted (shared devices, contractor accounts, or poorly managed logins).
- Identify the installed OS build/revision number for each affected machine (Settings → System → About, or run
winver). - Upgrade each affected system to the fixed Windows version for its release branch listed by Microsoft for CVE-2026-61360.
- If patching must be delayed, temporarily reduce risk by tightening access: remove unneeded user accounts, disable shared logins, and ensure only trusted accounts can sign in to the affected machines.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61360 and every CVE in our database. Create a free account — no credit card required.
Create Free Account