CVE-2026-45606
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Microsoft UxTheme Library

Vulnerability report for CVE-2026-45606, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-09

Last updated on: 2026-06-11

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-09
Last Modified
2026-06-11
Generated
2026-06-30
AI Q&A
2026-06-09
EPSS Evaluated
2026-06-28
NVD
EUVD

Affected Vendors & Products

Showing 24 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9234 (exc)
microsoft windows_10_1607 to 10.0.14393.9234 (exc)
microsoft windows_10_1809 to 10.0.17763.8880 (exc)
microsoft windows_10_1809 to 10.0.17763.8880 (exc)
microsoft windows_10_21h2 to 10.0.19044.7417 (exc)
microsoft windows_10_21h2 to 10.0.19044.7417 (exc)
microsoft windows_10_21h2 to 10.0.19044.7417 (exc)
microsoft windows_10_22h2 to 10.0.19045.7417 (exc)
microsoft windows_10_22h2 to 10.0.19045.7417 (exc)
microsoft windows_10_22h2 to 10.0.19045.7417 (exc)
microsoft windows_11_23h2 to 10.0.22631.7219 (exc)
microsoft windows_11_23h2 to 10.0.22631.7219 (exc)
microsoft windows_11_24h2 to 10.0.26100.8655 (exc)
microsoft windows_11_24h2 to 10.0.26100.8655 (exc)
microsoft windows_11_25h2 to 10.0.26200.8655 (exc)
microsoft windows_11_25h2 to 10.0.26200.8655 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_server_2016 to 10.0.14393.9234 (exc)
microsoft windows_server_2019 to 10.0.17763.8880 (exc)
microsoft windows_server_2022 to 10.0.20348.5256 (exc)
microsoft windows_server_2025 to 10.0.26100.32995 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

This vulnerability allows an authorized attacker to cause a local denial of service through an out-of-bounds read in the Microsoft UxTheme Library (uxtheme.dll).

Since the vulnerability does not impact confidentiality or integrity of data (CVSS indicates no impact on confidentiality or integrity), it is unlikely to directly affect compliance with data protection standards such as GDPR or HIPAA, which primarily focus on protecting personal data privacy and integrity.

However, denial of service could affect availability, which is a component of these standards, so organizations should consider the potential impact on system availability and ensure appropriate mitigations are in place.

Executive Summary

This vulnerability is an out-of-bounds read in the Microsoft UxTheme Library (uxtheme.dll). It allows an authorized attacker to cause a denial of service on the affected system locally.

Impact Analysis

The impact of this vulnerability is a denial of service, which means an attacker with local authorization can cause the affected system or service to become unavailable or crash.

Mitigation Strategies

This vulnerability allows an authorized attacker to cause a denial of service locally via an out-of-bounds read in the Microsoft UxTheme Library (uxtheme.dll).

To mitigate this vulnerability, ensure that only trusted and authorized users have local access to the affected system, as the attack requires local privileges.

Monitor for updates or patches from Microsoft addressing this issue and apply them promptly once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45606. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart