ZeroHour

CVE-2026-70296

mass

Out-of-Bounds Write RCE in Microsoft Windows Imaging Component

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
AI analysis

CVE-2026-70296 is a critical (CVSS 9.8) out-of-bounds write vulnerability (CWE-787) in the Windows Imaging Component (WIC), the built-in Microsoft Windows component that handles image and codec processing. Per the advisory and CVSS vector, an unauthorized attacker can trigger the flaw over a network without credentials or user interaction, though the available data does not specify the exact trigger path. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability of the affected system. Because WIC ships as a standard part of Windows, essentially every system running an affected Windows build is exposed until patched. As of the data available, there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 1.0% (60th percentile); fixes were distributed as part of Microsoft's September 2026 Patch Tuesday, with Snort detection rules published.

What to do: Apply the September 2026 Microsoft security updates for CVE-2026-70296 as soon as possible, prioritizing internet-facing and shared Windows systems, and verify against the affected builds listed in the Microsoft advisory. Until patched, deploy the Snort rules released alongside the September 2026 Patch Tuesday to detect exploitation attempts. Inventory Windows assets for pending Patch Tuesday status to confirm remediation coverage.

Affected
Microsoft Windows Imaging Component (component of Microsoft Windows)
Estimated exposure
masshundreds of millions of Windows endpoints (WIC is a built-in component on effectively all supported Windows installations) — Windows Imaging Component ships by default with supported Windows releases, so the potential installed base is the entire Windows ecosystem (hundreds of millions of devices), with the directly reachable subset depending on how the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs