ZeroHour

CVE-2026-70586

mass

Heap-Based Buffer Overflow RCE in Microsoft Windows Paint

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

A heap-based buffer overflow (CWE-122) in Microsoft's Windows Paint application can corrupt memory when the app processes crafted content, allowing an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/PR:N/UI:R) indicates the attack requires no privileges or authentication, but a user must be enticed into opening the malicious file (e.g., a crafted image delivered via email, chat, or web download) in Paint. Successful exploitation gives the attacker arbitrary code execution with high impact on confidentiality, integrity, and availability in the context of the affected user. Any Windows system running an affected Paint build is exposed; because Paint ships by default with Windows, the potential install base is enormous, though exact affected releases/builds are specified in Microsoft's advisory rather than in the summary data here. Exploitation status: no public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS assigns a 0.8% probability of exploitation within 30 days (55th percentile), so no confirmed in-the-wild exploitation is documented yet.

What to do: Apply the Paint security update Microsoft has issued for this CVE as soon as it is offered through your Windows/Store update channels, and verify installed Paint builds against the affected ranges in Microsoft's advisory. Until patched, discourage users from opening untrusted image files (email attachments, chat-shared files, downloads) in Paint. With no public PoC and low EPSS, this can be handled in the regular patch cycle, but the network-reachable RCE with no authentication justifies prioritization over non-security updates.

Affected
Microsoft Windows Paint (Paint application bundled with Windows)
Estimated exposure
masswell over 1 billion Windows devices potentially affected (Paint ships by default with Windows) — Microsoft Paint is bundled by default with the Windows operating system, which runs on more than a billion devices worldwide, so the affected install base is on the order of a billion systems; note that practical exploit reach is smaller…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.