Multiple Vulnerabilities in Windows GDI+ Disclosed

Multiple Vulnerabilities in Windows GDI+ Disclosed

First seen 10 Mar 2026, 17:28 UTC Api.Msrc.Microsoft 57.8

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in Windows GDI+ have been reported, affecting the ability of unauthorized attackers to disclose information and execute code. CVE-2026-25181 allows for information disclosure through an out-of-bounds read, while another CVE indicates an untrusted path that could enable local code execution. Both vulnerabilities were published on 2026-03-10.

Timeline

2026-03-10
CVE-2026-25181 published
2026-03-10
Second CVE related to GDI+ published