ZeroHour

CVE-2026-73023

mass

Heap buffer overflow in Microsoft Windows Imaging Component enables unauthenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-73023 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the Windows service responsible for decoding and processing image files. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a remote, unauthenticated attacker can trigger the flaw with low attack complexity, but user interaction is required, consistent with the victim opening or previewing a specially crafted image file delivered over a network (for example via email, web, or messaging). Successful exploitation grants the attacker code execution on the target system with high impact to confidentiality, integrity, and availability. Any system running the Windows Imaging Component is affected, which means effectively every supported Windows deployment. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.6% probability of exploitation within 30 days; remediation arrived with Microsoft's September 2026 Patch Tuesday updates.

What to do: Prioritize deployment of Microsoft's September 2026 Patch Tuesday security updates across the Windows estate, giving earliest attention to user-facing workstations and remote-worker endpoints where crafted image files are most likely to be opened. Until systems are patched, caution users against opening image files from untrusted or unsolicited sources and consider email/web filtering of unexpected image attachments. No public exploit exists yet and the flaw is not in CISA KEV, but the nonzero EPSS score means patching should not be deferred.

Affected
Microsoft Windows Imaging Component (WIC)
Estimated exposure
mass≈1 billion+ Windows devices (WIC ships with all supported Windows installations) — Windows Imaging Component is a default operating-system component present on supported Windows client and server releases, and public market data places Windows on well over a billion active devices, though successful exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.