ZeroHour

CVE-2026-83992

mass

Heap-Based Buffer Overflow RCE in Microsoft Windows Imaging Component

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

CVE-2026-83992 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the built-in Windows service that decodes image files. An unauthenticated remote attacker can trigger the overflow by convincing a user to open or preview a specially crafted image; the CVSS 8.8 vector (AV:N/AC:L/PR:N/UI:R) confirms no privileges are required but user interaction is needed. Successful exploitation yields remote code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. Effectively all Windows systems that parse images with WIC are plausibly affected, though the available data does not enumerate specific Windows version ranges. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days (47th percentile), indicating no known in-the-wild exploitation; the flaw was addressed in Microsoft's September 2026 Patch Tuesday, which fixed 973 vulnerabilities including two unrelated exploited zero-days.

What to do: Apply Microsoft's September 2026 Patch Tuesday Windows security updates across all endpoints and servers, prioritizing user-facing systems. Because exploitation requires user interaction, exercise caution with image files from untrusted sources (email attachments, downloads, preview panes) until patching is complete. Verify patch status by confirming the latest Windows cumulative update is installed on each system.

Affected
Microsoft Windows Imaging Component (WIC), a component of Microsoft Windows
Estimated exposure
masshundreds of millions of Windows devices (WIC is a default component present on essentially all Windows installations) — WIC ships by default with Windows, which runs on over a billion active devices worldwide, so effectively every unpatched Windows installation carries the vulnerable component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs