AI analysis
CVE-2026-83992 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the built-in Windows service that decodes image files. An unauthenticated remote attacker can trigger the overflow by convincing a user to open or preview a specially crafted image; the CVSS 8.8 vector (AV:N/AC:L/PR:N/UI:R) confirms no privileges are required but user interaction is needed. Successful exploitation yields remote code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. Effectively all Windows systems that parse images with WIC are plausibly affected, though the available data does not enumerate specific Windows version ranges. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days (47th percentile), indicating no known in-the-wild exploitation; the flaw was addressed in Microsoft's September 2026 Patch Tuesday, which fixed 973 vulnerabilities including two unrelated exploited zero-days.
What to do: Apply Microsoft's September 2026 Patch Tuesday Windows security updates across all endpoints and servers, prioritizing user-facing systems. Because exploitation requires user interaction, exercise caution with image files from untrusted sources (email attachments, downloads, preview panes) until patching is complete. Verify patch status by confirming the latest Windows cumulative update is installed on each system.
Affected
| Microsoft Windows Imaging Component (WIC), a component of Microsoft Windows | — |
Estimated exposure
masshundreds of millions of Windows devices (WIC is a default component present on essentially all Windows installations) — WIC ships by default with Windows, which runs on over a billion active devices worldwide, so effectively every unpatched Windows installation carries the vulnerable component.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.