ZeroHour

CVE-2026-73017

mass

Heap Buffer Overflow in Windows Graphics Kernel Enables Local Code Execution

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-73017 is a heap-based buffer overflow (CWE-122) in the Windows Graphics Kernel, fixed by Microsoft in its September 2026 security update release. It is triggered locally: per the CVSS vector, an attacker already holding high privileges on the target machine, with no user interaction and high attack complexity, must successfully exploit the memory corruption. A successful exploit yields code execution with a scope change, meaning the attacker's code runs beyond the vulnerable component's normal security context (typically the kernel), with high impact to confidentiality, integrity, and availability. All Windows systems running the affected builds are potentially exposed, but exploitation requires a local attacker who already has elevated credentials, which limits exposure to scenarios such as compromised accounts or privilege/sandbox-escape chains. No exploitation is currently known: the flaw is not in CISA KEV, has no public proof-of-concept, and EPSS assigns it only a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's September 2026 security updates to Windows systems during your next maintenance window, and verify installed builds against Microsoft's advisory to confirm the fix is present. Because exploitation requires local access with high privileges, treat this primarily as defense-in-depth and prioritize shared, multi-user, or server hosts. No public proof-of-concept or workarounds exist, so patching is the only reliable remediation.

Affected
Microsoft Windows (Graphics Kernel component)
Estimated exposure
masson the order of hundreds of millions of Windows devices — Windows runs on well over a billion active devices worldwide and the Graphics Kernel is a core component present in essentially every Windows client and server installation, although the specific affected builds are not stated in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.