MEDIUM · 6.5

CVE-2022-26934

Windows Graphics Component Information Disclosure Vulnerability

Vulnerability Description

Windows Graphics Component Information Disclosure Vulnerability

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Microsoft365 Apps-
MicrosoftOffice2019
MicrosoftOffice Long Term Servicing Channel2021
MicrosoftWindows 10 1507< 10.0.10240.19297
MicrosoftWindows 10 1607< 10.0.14393.5125
MicrosoftWindows 10 1809< 10.0.17763.2928
MicrosoftWindows 10 1909< 10.0.18363.2274
MicrosoftWindows 10 20H2< 10.0.19042.1706
MicrosoftWindows 10 21H1< 10.0.19043.1706
MicrosoftWindows 10 21H2< 10.0.19044.1706
MicrosoftWindows 11 21H2< 10.0.22000.675
MicrosoftWindows 7-
MicrosoftWindows 8.1-
MicrosoftWindows Rt 8.1-
MicrosoftWindows Server2022
MicrosoftWindows Server 2008r2
MicrosoftWindows Server 2012-
MicrosoftWindows Server 2016-
MicrosoftWindows Server 2019-
MicrosoftWindows Server 2022-

References

FAQ

What is CVE-2022-26934?

CVE-2022-26934 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Windows Graphics Component Information Disclosure Vulnerability

How severe is CVE-2022-26934?

CVE-2022-26934 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-26934?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft 365 Apps, Microsoft Office, Microsoft Office Long Term Servicing Channel, Microsoft Windows 10 1507, Microsoft Windows 10 1607.