
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25190 is an untrusted search path (DLL hijacking) vulnerability in the Windows Graphics Device Interface (GDI) component that allows an unauthorized local attacker to execute arbitrary code. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2/2016/2019/2022/2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-426 (Untrusted Search Path) and stems from improper search path handling in the Windows GDI component, enabling DLL hijacking. An attacker can place a malicious DLL in a directory that GDI searches before the legitimate system path, causing the malicious library to be loaded and executed. Exploitation requires local access and user interaction (e.g., opening a crafted file or running an application that triggers the vulnerable GDI code path), but requires no privileges. The MITRE ATT&CK technique associated with this vulnerability is T1574.007 (Path Interception by PATH Environment Variable) (Microsoft MSRC).
Successful exploitation results in local arbitrary code execution with high impact to confidentiality, integrity, and availability — all rated HIGH. An attacker who exploits this vulnerability could read sensitive data, modify system files, install malware, or disrupt system operations, potentially achieving complete system compromise. While the attack vector is local and requires user interaction, a compromised system could serve as a pivot point for lateral movement within a network (Microsoft MSRC).
gdi32.dll, gdiplus.dll); newly created or modified DLLs in non-standard locations.ImageLoad events with DLL paths outside %SystemRoot%\System32.Microsoft released patches on March 10, 2026 addressing this vulnerability across all affected platforms. Administrators should apply the following minimum build versions: Windows 10 21H2 → 10.0.19044.7058, Windows 10 22H2 → 10.0.19045.7058, Windows 11 23H2 → 10.0.22631.6783, Windows 11 24H2 → 10.0.26100.7979, Windows 11 25H2 → 10.0.26200.7979, Windows 11 26H1 → 10.0.28000.1719, Windows Server 2016 → 10.0.14393.8957, Windows Server 2019 → 10.0.17763.8511, Windows Server 2022 → 10.0.20348.4830, Windows Server 2022 23H2 → 10.0.25398.2207, Windows Server 2025 → 10.0.26100.32463. As a workaround where patching is not immediately possible, restrict write access to application directories, educate users to avoid opening files from untrusted sources, and monitor for suspicious DLL loading activity (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday reporting by multiple security outlets. Rapid7, Sophos, Zero Day Initiative, and SANS ISC all included it in their Patch Tuesday roundups, noting it as one of 79+ vulnerabilities addressed that month (Rapid7 Blog, Sophos Blog, ZDI Blog, SANS ISC). Community reaction was measured, with no significant alarm given the absence of public exploits or active exploitation at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."