Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2026-65662
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Windows GDI when processing a specially crafted Enhanced Metafile (EMF). A local user can provide a specially crafted EMF to disclose sensitive information.
The disclosed data is limited to small portions of adjacent memory from the affected application at the time the file is processed.
Affected software
Windows Server
How to mitigate CVE-2026-65662
Windows Server - addressed in versions 2012 R2 6.3.9600.23337, 2012 6.2.9200.26279, 2016 10.0.14393.9418, 2019 10.0.17763.9115, 2022 10.0.20348.5440, 2022 10.0.20348.5499, 2025 10.0.26100.33222, 2025 10.0.26100.33296