Heap buffer overflow in Microsoft Windows Imaging Component enables unauthenticated RCE
AI analysis
CVE-2026-73023 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the Windows service responsible for decoding and processing image files. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a remote, unauthenticated attacker can trigger the flaw with low attack complexity, but user interaction is required, consistent with the victim opening or previewing a specially crafted image file delivered over a network (for example via email, web, or messaging). Successful exploitation grants the attacker code execution on the target system with high impact to confidentiality, integrity, and availability. Any system running the Windows Imaging Component is affected, which means effectively every supported Windows deployment. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.6% probability of exploitation within 30 days; remediation arrived with Microsoft's September 2026 Patch Tuesday updates.
What to do: Prioritize deployment of Microsoft's September 2026 Patch Tuesday security updates across the Windows estate, giving earliest attention to user-facing workstations and remote-worker endpoints where crafted image files are most likely to be opened. Until systems are patched, caution users against opening image files from untrusted or unsolicited sources and consider email/web filtering of unexpected image attachments. No public exploit exists yet and the flaw is not in CISA KEV, but the nonzero EPSS score means patching should not be deferred.
Affected
| Microsoft Windows Imaging Component (WIC) | — |
Estimated exposure
mass≈1 billion+ Windows devices (WIC ships with all supported Windows installations) — Windows Imaging Component is a default operating-system component present on supported Windows client and server releases, and public market data places Windows on well over a billion active devices, though successful exploitation…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.