CVE-2025-50176

HIGH

Graphics Kernel - Code Injection

Title source: llm
STIX 2.1

Description

Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843 CWE-122
Status published
Products (6)
microsoft/windows_11_22h2 < 10.0.22621.5768
microsoft/windows_11_23h2 < 10.0.22631.5768
microsoft/windows_11_24h2 < 10.0.26100.4851
microsoft/windows_server_2022 < 10.0.20348.3989
microsoft/windows_server_2022_23h2 < 10.0.25398.1791
microsoft/windows_server_2025 < 10.0.26100.4851
Published Aug 12, 2025
Tracked Since Feb 18, 2026