ZeroHour

CVE-2026-73016

mass

Heap-Based Buffer Overflow in Microsoft Graphics Component Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
AI analysis

A heap-based buffer overflow (CWE-122) in Microsoft's Graphics Component, the graphics rendering code shipped with Windows, can be triggered over a network. According to the CVSS vector, an unauthenticated attacker requires user interaction (UI:R), meaning a victim must typically open or preview attacker-supplied content such as a crafted file, image, or document for the memory corruption to occur. Successful exploitation yields remote code execution with the privileges of the logged-in user, producing high confidentiality, integrity, and availability impact. Any system containing the affected component is exposed, which in practice means broadly deployed Windows installations, though only users who interact with malicious content are reachable. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.6% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is available, checking Microsoft's advisory for the exact affected builds since versions were not specified in the source data. Until systems are patched, treat unsolicited files, images, and email attachments as untrusted and do not open or preview them from unknown sources. No public proof-of-concept or documented workarounds exist yet, so patching is the primary mitigation.

Affected
Microsoft Graphics Component (Windows graphics rendering component)
Estimated exposure
mass≈1 billion+ Windows installations include the component, though only users opening crafted content are practically reachable — The Microsoft Graphics Component ships as part of Windows, so the affected population is essentially the entire Windows installed base (well over a billion devices), with actual attack reach limited by the required user interaction.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.