Heap Buffer Overflow in Microsoft Windows Imaging Component (ICC Parsing)
CVSS 3.1
7.8high
EPSS
<1%p47
Published
()
Modified
AI analysis
CVE-2026-54984 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component, the core imaging and color-management engine built into Windows. Related advisory coverage (ZDI-26-543) ties the flaw to an out-of-bounds write while parsing ICC color-profile data embedded in image files, meaning a crafted image containing a malicious ICC profile triggers the bug when a user opens, previews, or otherwise processes it. Because the CVSS vector is AV:L with UI:R, exploitation requires user interaction rather than a network-facing service; a successful attacker executes code with the privileges of the local user, with high impact to confidentiality, integrity, and availability. Nearly every supported Windows deployment is affected, since the listed versions span Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2012 through 2022. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation odds at about 0.6%, so no in-the-wild exploitation is known at this time.
What to do: Apply Microsoft's security update for CVE-2026-54984 across all affected Windows 10, Windows 11, and Windows Server systems, prioritizing machines and servers that process untrusted images (email attachments, browser downloads, shared folders, thumbnail/print pipelines); older Windows 10 releases and Windows Server 2012 may only receive the fix via extended support channels such as ESU. Until patched, instruct users not to open image files from untrusted sources and review any automated processing of untrusted images with ICC profiles attached. Verify remediation by confirming the relevant Microsoft security update is installed on each affected release rather than relying on a single KB across all versions.
Affected
microsoft Windows 10
1607, 1809, 21H2, 22H2
microsoft Windows 11
23H2, 24H2, 25H2, 26H1
microsoft Windows Server
2012, 2016, 2019, 2022
Estimated exposure
masshundreds of millions of unpatched Windows 10/11 client and Windows Server installations — Windows Imaging Component ships with every listed Windows client and server release, and the combined Windows 10/11 installed base is on the order of a billion devices, so the unpatched population is plausibly in the hundreds of millions.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
ZDI discloses an out-of-bounds write in Windows ICC file parsing via Mscms.dll enabling remote code execution (CVE-2026-54984, CVSS 7.8).
ZDI advisory ZDI-26-543 describes an out-of-bounds write in Microsoft Windows ICC file parsing that allows remote attackers to execute arbitrary code. Exploitation requires interaction with the Mscms.dll color management library, though attack vectors may vary by implementation. The flaw has a CVSS rating of 7.8 and is assigned CVE-2026-54984.