ZeroHour

CVE-2026-78439

mass

Stack-Based Buffer Overflow in Microsoft Graphics Component Enables Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-78439 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, rated High severity (CVSS 3.1: 8.8). It is reachable over a network without authentication, but the CVSS vector includes UI:R (user interaction required), meaning an attacker most plausibly triggers it by convincing a user to open or preview attacker-supplied content such as a crafted file. Successful exploitation gives the attacker code execution in the context of the local user, with high impact on confidentiality, integrity, and availability. Any Windows system running an affected version of the Graphics Component is potentially exposed; the source data does not enumerate specific Windows versions or builds, so defenders should check Microsoft's September 2026 security release for the exact affected ranges. There is currently no known in-the-wild exploitation, no public proof of concept, and the flaw is not listed in CISA's KEV, with EPSS assigning a 0.6% probability of exploitation within 30 days (48th percentile).

What to do: Apply the Windows/Graphics Component fixes included in Microsoft's September 2026 security updates across all endpoints, prioritizing user workstations where file previewing is common. Until systems are patched, encourage users not to open or preview untrusted files and email attachments. Because exploitation requires user interaction and there is no public PoC or KEV listing, normal monthly patching cadence is likely adequate, but monitor Microsoft's advisory for revised affected-version details.

Affected
Microsoft Graphics Component (ships with Windows)
Estimated exposure
mass≈1 billion Windows devices (Graphics Component is a core component present on effectively all Windows installs) — The Graphics Component ships with every Windows installation and Windows' global install base is estimated at over a billion devices, though actual exploitation additionally requires user interaction with malicious content.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.