AI analysis
CVE-2026-83990 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, the Windows component that processes graphics operations. Per the CVSS vector, a local, low-privileged authorized user can trigger the overflow without user interaction, corrupting a stack buffer in the component. A successful attacker elevates privileges locally, gaining higher (typically administrator/SYSTEM-level) rights with high impact on confidentiality, integrity, and availability on the host. Any system shipping the Graphics Component is affected; specific version ranges were not enumerated in the source data, and fixes ship in Microsoft's September 2026 security updates. There is no public PoC, the flaw is not in CISA KEV, and EPSS is low (0.3%), so exploitation is not confirmed; it was patched as part of September 2026 Patch Tuesday, which also addressed two separately exploited zero-days.
What to do: Apply Microsoft's September 2026 security updates (Patch Tuesday) to all Windows clients and servers via Windows Update, WSUS, or Intune/ConfigMgr, since no public PoC or workaround is known. Prioritize systems that expose interactive logon to untrusted or standard users, such as RDP hosts, terminal servers, and shared workstations, because local access is required for exploitation. Confirm deployment of the September 2026 updates in your patch-management reporting before marking this CVE closed.
Affected
| Microsoft Graphics Component (shipped with Microsoft Windows) | — |
Estimated exposure
mass≈1 billion+ Windows devices (Graphics Component present across the Windows install base) — The Graphics Component ships with essentially all supported Windows client and server installs and the Windows install base is on the order of a billion-plus devices, though practical exploit exposure is limited to hosts granting…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.