ZeroHour

CVE-2026-77493

mass

Double-free RCE in Microsoft Graphics Component affects Windows and Windows Server

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
AI analysis

CVE-2026-77493 is a double-free memory corruption flaw (CWE-415) in the Microsoft Graphics Component, rated critical at CVSS 9.8. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated attacker can reach the vulnerable code over the network with no user interaction, delivering crafted input that causes the component to free the same memory allocation twice, corrupting the heap. Successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability. The affected CPE list spans Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012, 2016, 2019, and 2022, effectively covering the currently supported Windows client and server releases named in the data. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 1% probability of exploitation within the next 30 days (60th percentile).

What to do: Apply Microsoft's security update for CVE-2026-77493 through Windows Update or your patch-management channel as soon as it is published, prioritizing internet-facing Windows Servers (2012/2016/2019/2022) and remote-access endpoints because the flaw is network-exploitable without authentication or user interaction. Inventory Windows builds against the affected version list to confirm scope, and watch for KEV listing or public PoC releases as triggers to expedite emergency patching. No workarounds are documented in the available data.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows 1125H2
microsoft Windows 1126H1
microsoft Windows Server 20122012
microsoft Windows Server 20162016
microsoft Windows Server 20192019
microsoft Windows Server 20222022
Estimated exposure
masshundreds of millions of systems (essentially all Windows 10/11 client and Windows Server installations running the listed releases) — Windows runs on well over a billion devices worldwide and the listed versions span every supported Windows client and server release named in the CPE data, so theGraphics Component defect plausibly touches the bulk of the supported Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.