CVE-2026-73016
massHeap-Based Buffer Overflow in Microsoft Graphics Component Enables Remote Code Execution
A heap-based buffer overflow (CWE-122) in Microsoft's Graphics Component, the graphics rendering code shipped with Windows, can be triggered over a network. According to the CVSS vector, an unauthenticated attacker requires user interaction (UI:R), meaning a victim must typically open or preview attacker-supplied content such as a crafted file, image, or document for the memory corruption to occur. Successful exploitation yields remote code execution with the privileges of the logged-in user, producing high confidentiality, integrity, and availability impact. Any system containing the affected component is exposed, which in practice means broadly deployed Windows installations, though only users who interact with malicious content are reachable. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.6% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is available, checking Microsoft's advisory for the exact affected builds since versions were not specified in the source data. Until systems are patched, treat unsolicited files, images, and email attachments as untrusted and do not open or preview them from unknown sources. No public proof-of-concept or documented workarounds exist yet, so patching is the primary mitigation.
| Microsoft Graphics Component (Windows graphics rendering component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.