ZeroHour

CVE-2026-73013

mass

Heap-Based Buffer Overflow in Windows Imaging Component Enables Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-73013 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component, the built-in Windows framework that decodes and processes image files. The flaw is reachable over the network but requires user interaction (CVSS AV:N with UI:R): an unauthenticated ('unauthorized') attacker must get a user to open or preview a specially crafted image — for example via an email attachment or web-delivered file — causing heap memory corruption in the imaging pipeline. Successful exploitation yields remote code execution running as the logged-on user, with high-rated impacts on confidentiality, integrity, and availability. Any user of the affected Windows versions that ship Windows Imaging Component is exposed, and the issue was addressed as part of Microsoft's September 2026 Patch Tuesday. Exploitation is currently not known: there is no public proof-of-concept, the CVE is not in the CISA KEV catalog, and EPSS assigns a 0.6% probability of exploitation within 30 days (45th percentile).

What to do: Deploy the September 2026 Windows security updates from Microsoft as soon as possible, prioritizing endpoints whose users routinely handle images and documents from untrusted sources. Check Microsoft's advisory for the exact affected Windows versions and builds applicable to your fleet. Until patched, caution users against opening image files from untrusted senders or websites; no in-the-wild exploits or public PoCs are currently known.

Affected
Microsoft Windows Imaging Component (WIC)
Estimated exposure
masshundreds of millions of Windows installations (WIC ships as a built-in component of Windows) — Windows Imaging Component is present by default on effectively all supported Windows client and server releases, so the exposed population is on the order of hundreds of millions to a billion-plus installations, though actually triggering…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.