ZeroHour

CVE-2026-81955

mass

Heap Buffer Overflow RCE in Microsoft Graphics Component (Windows)

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

CVE-2026-81955 is a heap-based buffer overflow (CWE-122) in Microsoft's Graphics Component, a built-in Windows component used to parse and render graphics content. Per Microsoft's CNA description, an unauthorized attacker can trigger the flaw remotely by delivering crafted content that the component processes; the CVSS vector (AV:N/PR:N/UI:R) indicates the attack comes over a network without authentication but requires user interaction, such as opening or previewing a maliciously crafted file or content. Successful exploitation yields arbitrary code execution with full confidentiality, integrity, and availability impact, most likely in the context of the logged-on user. All Windows installations that include the affected Graphics Component are potentially affected; specific Windows version ranges are not included in the data provided and should be confirmed against Microsoft's advisory. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a 0.6% probability of exploitation within 30 days (47th percentile).

What to do: Apply Microsoft's security update for CVE-2026-81955 as soon as it is available via Windows Update, confirming affected Windows versions in Microsoft's advisory since the data here does not include version ranges. Prioritize systems where users routinely open untrusted files or browse untrusted content, and remind users not to open or preview unsolicited documents and media until patching is complete. There is no public PoC or known in-the-wild exploitation yet, but the 8.8 CVSS score warrants prompt patching rather than waiting for exploitation activity.

Affected
Microsoft Windows (Microsoft Graphics Component)
Estimated exposure
mass>1 billion Windows devices potentially affected (patch status varies) — Microsoft has publicly reported over one billion active Windows devices and the Graphics Component ships with Windows, so the theoretical exposure footprint is effectively the entire Windows install base, reduced in practice by systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.