ZeroHour

CVE-2026-77495

mass

Heap-Based Buffer Overflow RCE in Microsoft Windows Imaging Component

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-77495 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the Windows subsystem that decodes and processes image files. The CVSS vector (AV:N/PR:N/UI:R) indicates an unauthenticated remote attacker can exploit it, but only with user interaction — typically by getting a user to open, view or preview a crafted image that WIC then decodes, for example in a viewer or file-explorer thumbnail pane. Successful exploitation yields remote code execution with the privileges of the current user, with high impact on confidentiality, integrity and availability. Any Windows system that uses WIC to handle images is affected — effectively the entire installed Windows base — and the flaw was fixed in Microsoft's September 2026 Patch Tuesday. It is not yet known to be exploited in the wild: there is no public proof-of-concept, it is absent from CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.6%.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates as soon as possible on all Windows endpoints and servers, prioritizing user workstations where untrusted image files (email attachments, downloads, shared drives, web content) are routinely viewed. Until patched, treat unexpected image files as risky and note that previewing them (e.g., thumbnail/preview panes) can trigger the flaw. No exploitation is currently observed and no public PoC exists, so mass exploitation is unlikely but may follow disclosure.

Affected
Microsoft Windows Imaging Component (shipped with Windows operating systems)Windows versions addressed in the September 2026 security updates (specific version ranges not enumerated in the available data; all affected Windows editions r
Estimated exposure
mass≈1 billion+ Windows installations (WIC is a built-in component of essentially all modern Windows desktops and servers) — Windows Imaging Component is a core, default-enabled part of the Windows OS, so the exposed population is on the order of the entire Windows install base rather than a separately installed product with countable installs.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.