ZeroHour

CVE-2026-83990

mass

Local Privilege Escalation via Stack Overflow in Microsoft Graphics Component

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-83990 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, the Windows component that processes graphics operations. Per the CVSS vector, a local, low-privileged authorized user can trigger the overflow without user interaction, corrupting a stack buffer in the component. A successful attacker elevates privileges locally, gaining higher (typically administrator/SYSTEM-level) rights with high impact on confidentiality, integrity, and availability on the host. Any system shipping the Graphics Component is affected; specific version ranges were not enumerated in the source data, and fixes ship in Microsoft's September 2026 security updates. There is no public PoC, the flaw is not in CISA KEV, and EPSS is low (0.3%), so exploitation is not confirmed; it was patched as part of September 2026 Patch Tuesday, which also addressed two separately exploited zero-days.

What to do: Apply Microsoft's September 2026 security updates (Patch Tuesday) to all Windows clients and servers via Windows Update, WSUS, or Intune/ConfigMgr, since no public PoC or workaround is known. Prioritize systems that expose interactive logon to untrusted or standard users, such as RDP hosts, terminal servers, and shared workstations, because local access is required for exploitation. Confirm deployment of the September 2026 updates in your patch-management reporting before marking this CVE closed.

Affected
Microsoft Graphics Component (shipped with Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows devices (Graphics Component present across the Windows install base) — The Graphics Component ships with essentially all supported Windows client and server installs and the Windows install base is on the order of a billion-plus devices, though practical exploit exposure is limited to hosts granting…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs