CVE-2026-25169
vulnerability analysis and mitigation

Overview

CVE-2026-25169 is a divide-by-zero vulnerability in the Microsoft Graphics Component that allows a local, unprivileged attacker to trigger a denial-of-service condition. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a broad range of Windows client and server operating systems including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-369 (Divide By Zero), occurring within the Microsoft Graphics Component when processing certain input that results in a division-by-zero arithmetic error. An attacker with low-privilege local access can trigger this flaw without requiring user interaction or elevated privileges, causing the affected graphics subsystem to crash and resulting in a denial-of-service condition. No user interaction is required, and the scope of impact remains unchanged (confined to the vulnerable component). No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).

Impact

Successful exploitation results in a denial-of-service condition, specifically causing system unavailability or service disruption on the affected host. The vulnerability has no impact on confidentiality or integrity — only availability is affected (rated HIGH). Because the attack is local and does not facilitate code execution or privilege escalation, lateral movement potential is limited, though disruption of graphics-dependent services on critical systems (e.g., servers running graphical workloads) could have operational consequences (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches for CVE-2026-25169 as part of the March 10, 2026 Patch Tuesday security update cycle. Administrators should update affected systems to the following minimum versions: Windows 10 v1607/Server 2016 (10.0.14393.8957+), Windows 10 v1809/Server 2019 (10.0.17763.8511+), Windows 10 v21H2 (10.0.19044.7058+), Windows 10 v22H2 (10.0.19045.7058+), Windows 11 v23H2 (10.0.22631.6783+), Windows 11 v24H2 (10.0.26100.7979+), Windows 11 v25H2 (10.0.26200.7979+), Windows 11 v26H1 (10.0.28000.1719+), Windows Server 2022 (10.0.20348.4830+), Windows Server 2022 23H2 (10.0.25398.2207+), and Windows Server 2025 (10.0.26100.32463+). As a compensating control, restricting local user access to sensitive systems can reduce exposure until patching is complete (Microsoft MSRC).

Community reactions

CVE-2026-25169 was covered as part of broader March 2026 Patch Tuesday roundups by several security outlets. Sophos, Rapid7, Zero Day Initiative, and ISC SANS all published summaries of the March 2026 update cycle, noting the overall patch batch addressed 79 vulnerabilities including two zero-days; CVE-2026-25169 received minimal individual attention given its medium severity and local-only attack vector (Sophos Blog, Rapid7 Blog, ZDI Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management