ZeroHour

CVE-2026-73006

mass

Stack-Based Buffer Overflow RCE in Microsoft Graphics Component

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-73006 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component that an unauthenticated attacker can exploit remotely to execute code. The CVSS vector (AV:N/PR:N/UI:R) indicates the attack requires user interaction, meaning it is most likely triggered when a user opens or previews attacker-supplied content, such as a crafted document or image, that the Graphics Component renders. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, typically in the context of the application or user handling the content. Affected systems are those running the impacted Microsoft software that includes the Graphics Component; specific product lists and version ranges are not enumerated in the available data, though related coverage ties the fix to Microsoft's September 2026 security updates. Exploitation is not currently observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 0.8% probability of exploitation within 30 days (55th percentile).

What to do: Apply Microsoft's September 2026 security updates to all Windows systems as soon as feasible, prioritizing hosts that process untrusted files such as workstations, mail clients, and file-handling servers. No workaround is documented in the available data; because user interaction is required, caution around opening or previewing untrusted documents and images adds defense in depth. Verify patch compliance through Windows Update/WSUS and your vulnerability management tooling.

Affected
Microsoft Graphics Component
Estimated exposure
masseffectively every supported Windows installation — on the order of 1 billion+ devices — The Graphics Component ships as a core rendering library on essentially all Windows machines, and Microsoft's Windows install base is publicly estimated at over a billion devices, though the portion of hosts with the specific vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.