ZeroHour

CVE-2026-73018

mass

Heap Buffer Overflow in Microsoft Graphic Fonts Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-73018 is a heap-based buffer overflow (CWE-122) in Microsoft's Graphic Fonts component, disclosed and fixed through Microsoft's September 2026 security update cycle. Per the CVSS vector (AV:N/AC:L/PR:N/UI:R), a remote, unauthenticated attacker can trigger the flaw with crafted font/graphics content that a user must render, for example by opening a malicious document or viewing untrusted content in an affected application. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (base score 8.8). Any user of Microsoft products that include the Graphic Fonts component is potentially affected, though the source data does not enumerate the exact product names or version ranges. There is no known exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only about a 0.8% chance of exploitation within 30 days (53rd percentile), but patching is still warranted given the RCE impact.

What to do: Apply Microsoft's September 2026 security updates as soon as practical, prioritizing user-facing systems (workstations, terminal/VDI hosts) where untrusted documents, email, or web content is rendered, and check Microsoft's advisory for the exact affected product/version list, which was not included in the source data. Because the attack requires user interaction (UI:R), mail/web content filtering and caution with untrusted font-bearing files reduce exposure while patching is underway. Monitor for updates to KEV and EPSS given the component's broad deployment.

Affected
Microsoft Graphic Fonts (graphics/font rendering component)
Estimated exposure
mass~10^8-10^9 Microsoft endpoints (installed-base estimate) — Microsoft is the assigning vendor and its font/graphics components ship as part of its OS and Office estate, whose installed base is publicly estimated in the hundreds of millions to over a billion devices, so exposure is conservatively…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.