CVE-2026-21219
Microsoft · Published January 13, 2026
7.0
CVSS v3.1
HIGHPatch availableGet patch
Description
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Affected Products
- Windows SDK
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C