
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25169 is a divide-by-zero vulnerability in the Microsoft Graphics Component that allows a local, unprivileged attacker to trigger a denial-of-service condition. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a broad range of Windows client and server operating systems including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC).
The vulnerability is classified as CWE-369 (Divide By Zero), occurring within the Microsoft Graphics Component when processing certain input that results in a division-by-zero arithmetic error. An attacker with low-privilege local access can trigger this flaw without requiring user interaction or elevated privileges, causing the affected graphics subsystem to crash and resulting in a denial-of-service condition. No user interaction is required, and the scope of impact remains unchanged (confined to the vulnerable component). No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).
Successful exploitation results in a denial-of-service condition, specifically causing system unavailability or service disruption on the affected host. The vulnerability has no impact on confidentiality or integrity — only availability is affected (rated HIGH). Because the attack is local and does not facilitate code execution or privilege escalation, lateral movement potential is limited, though disruption of graphics-dependent services on critical systems (e.g., servers running graphical workloads) could have operational consequences (Microsoft MSRC).
Microsoft released patches for CVE-2026-25169 as part of the March 10, 2026 Patch Tuesday security update cycle. Administrators should update affected systems to the following minimum versions: Windows 10 v1607/Server 2016 (10.0.14393.8957+), Windows 10 v1809/Server 2019 (10.0.17763.8511+), Windows 10 v21H2 (10.0.19044.7058+), Windows 10 v22H2 (10.0.19045.7058+), Windows 11 v23H2 (10.0.22631.6783+), Windows 11 v24H2 (10.0.26100.7979+), Windows 11 v25H2 (10.0.26200.7979+), Windows 11 v26H1 (10.0.28000.1719+), Windows Server 2022 (10.0.20348.4830+), Windows Server 2022 23H2 (10.0.25398.2207+), and Windows Server 2025 (10.0.26100.32463+). As a compensating control, restricting local user access to sensitive systems can reduce exposure until patching is complete (Microsoft MSRC).
CVE-2026-25169 was covered as part of broader March 2026 Patch Tuesday roundups by several security outlets. Sophos, Rapid7, Zero Day Initiative, and ISC SANS all published summaries of the March 2026 update cycle, noting the overall patch batch addressed 79 vulnerabilities including two zero-days; CVE-2026-25169 received minimal individual attention given its medium severity and local-only attack vector (Sophos Blog, Rapid7 Blog, ZDI Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."