AI analysis
CVE-2026-77495 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the Windows subsystem that decodes and processes image files. The CVSS vector (AV:N/PR:N/UI:R) indicates an unauthenticated remote attacker can exploit it, but only with user interaction — typically by getting a user to open, view or preview a crafted image that WIC then decodes, for example in a viewer or file-explorer thumbnail pane. Successful exploitation yields remote code execution with the privileges of the current user, with high impact on confidentiality, integrity and availability. Any Windows system that uses WIC to handle images is affected — effectively the entire installed Windows base — and the flaw was fixed in Microsoft's September 2026 Patch Tuesday. It is not yet known to be exploited in the wild: there is no public proof-of-concept, it is absent from CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.6%.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates as soon as possible on all Windows endpoints and servers, prioritizing user workstations where untrusted image files (email attachments, downloads, shared drives, web content) are routinely viewed. Until patched, treat unexpected image files as risky and note that previewing them (e.g., thumbnail/preview panes) can trigger the flaw. No exploitation is currently observed and no public PoC exists, so mass exploitation is unlikely but may follow disclosure.
Affected
| Microsoft Windows Imaging Component (shipped with Windows operating systems) | Windows versions addressed in the September 2026 security updates (specific version ranges not enumerated in the available data; all affected Windows editions r |
Estimated exposure
mass≈1 billion+ Windows installations (WIC is a built-in component of essentially all modern Windows desktops and servers) — Windows Imaging Component is a core, default-enabled part of the Windows OS, so the exposed population is on the order of the entire Windows install base rather than a separately installed product with countable installs.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.