ZeroHour

CVE-2026-69499

mass

Integer Overflow RCE in Microsoft Windows Imaging Component

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69499 is an integer overflow/wraparound flaw (CWE-190) in the Windows Imaging Component (WIC), the Windows subsystem that decodes image formats such as those used by photos, previews, and thumbnails. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an unauthenticated remote attacker must induce user interaction, most plausibly by having a user open or preview a specially crafted image file delivered over a network. Successful exploitation would allow the attacker to execute arbitrary code in the context of the affected user, with high impact on confidentiality, integrity, and availability. Because WIC is a built-in Windows component, any Windows system that processes images from untrusted sources is affected; the source data does not enumerate specific affected Windows versions. As of the reported data there is no known exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with EPSS estimating only a 0.8% chance of exploitation within 30 days.

What to do: Install the Windows security updates released in Microsoft's September 2026 Patch Tuesday as they become available to your environment, prioritizing endpoints and servers where users routinely open untrusted image files. Because the affected Windows version list was not provided in the source data, consult Microsoft's advisory to confirm which builds your estate runs and ensure updates cover them. There are no published workarounds, so patching is the primary mitigation; monitor the dashboard for exploitation indicators given the EPSS score may rise if a PoC emerges.

Affected
Microsoft Windows Imaging Component (component of Microsoft Windows)Affected Windows versions not enumerated in the available data; check Microsoft's September 2026 security update advisory for the full version list
Estimated exposure
mass≈hundreds of millions to 1B+ Windows installations (WIC ships with Windows) — WIC is a standard built-in component of the Windows operating system, so exposure is effectively the global Windows installed base, commonly estimated at over a billion devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs