ZeroHour

CVE-2026-69467

mass

Stack Buffer Overflow in Microsoft Graphics Component Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-69467 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, a core graphics-parsing component shipped with Windows. An attacker who already has the ability to run code on a machine with only low (standard-user) privileges can trigger the overflow from a local process, with no user interaction required. Successful exploitation allows the attacker to execute code with elevated privileges on the affected host, with high impact on the confidentiality, integrity, and availability of the system. All Windows systems running the affected versions of the Graphics Component are in scope, though the specific affected Windows version ranges are not stated in the data available here. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS score of 0.3% indicates no confirmed exploitation in the wild.

What to do: Monitor Microsoft's advisory for the affected Windows versions and apply the security update promptly once released, prioritizing multi-user, shared, and terminal/RDS-style systems where local privilege escalation has the greatest impact. Until patched, reduce risk by restricting execution of untrusted local code and keeping users on standard (non-admin) accounts. With no public PoC, no KEV listing, and a low EPSS score, treat this as lower urgency than internet-facing flaws, but do not defer patching on systems used by untrusted or multiple users.

Affected
Microsoft Graphics Component (shipped with Windows)
Estimated exposure
mass≈1 billion+ Windows devices (Graphics Component ships with Windows) — The Graphics Component is a core part of Windows, and Microsoft publicly reports an active installed base of over one billion Windows devices, so plausible exposure is on the order of hundreds of millions to more than a billion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.