ZeroHour

CVE-2026-69586

mass

Integer Overflow RCE in Microsoft Windows PDF Component

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69586 is an integer overflow or wraparound flaw (CWE-190) in the Microsoft Windows PDF component that leads to a memory corruption condition (CWE-122) when the component processes crafted PDF data. Per Microsoft's scoring, an unauthenticated network attacker can trigger it remotely without privileges or user interaction, although the affected version ranges are not specified in the available data. Successful exploitation allows the attacker to execute arbitrary code on the target system, with the CVSS score indicating full confidentiality, integrity, and availability impact. Any system running the affected Windows PDF component is exposed, which in practice means an extremely large share of the Windows installed base. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and an EPSS probability of about 1.0% over the next 30 days, indicating no known in-the-wild exploitation so far.

What to do: Install Microsoft's security update for CVE-2026-69586 as soon as it is published (Patch Tuesday release), and verify applicability against your Windows builds since no version ranges are provided in this data. Until patching, avoid opening untrusted PDFs and limit automated PDF preview or processing where feasible. With no public PoC or known exploitation, patch in the normal maintenance cycle but do not defer past the next available update.

Affected
Microsoft Windows PDF component
Estimated exposure
mass>1 billion Windows installations (component ships with the OS) — The PDF component is built into Windows, which runs on well over a billion devices worldwide, so potential exposure is bounded only by the Windows installed base even though actual exploitation requires the component to process…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.