CyberICT

CVE-2026-21219

Microsoft · Published January 13, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Affected Products

  • Windows SDK

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C