CVE-2026-69467
massStack Buffer Overflow in Microsoft Graphics Component Allows Local Privilege Escalation
CVE-2026-69467 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, a core graphics-parsing component shipped with Windows. An attacker who already has the ability to run code on a machine with only low (standard-user) privileges can trigger the overflow from a local process, with no user interaction required. Successful exploitation allows the attacker to execute code with elevated privileges on the affected host, with high impact on the confidentiality, integrity, and availability of the system. All Windows systems running the affected versions of the Graphics Component are in scope, though the specific affected Windows version ranges are not stated in the data available here. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS score of 0.3% indicates no confirmed exploitation in the wild.
What to do: Monitor Microsoft's advisory for the affected Windows versions and apply the security update promptly once released, prioritizing multi-user, shared, and terminal/RDS-style systems where local privilege escalation has the greatest impact. Until patched, reduce risk by restricting execution of untrusted local code and keeping users on standard (non-admin) accounts. With no public PoC, no KEV listing, and a low EPSS score, treat this as lower urgency than internet-facing flaws, but do not defer patching on systems used by untrusted or multiple users.
| Microsoft Graphics Component (shipped with Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.