ZeroHour

CVE-2026-84000

mass

Heap Buffer Overflow in Microsoft Graphics Component Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-84000 is a heap-based buffer overflow (CWE-122) involving an integer-overflow condition (CWE-190) in the Microsoft Graphics Component. An attacker who is already authorized on the machine with low privileges can trigger the overflow locally, with no user interaction required per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation yields local code execution with high impact on confidentiality, integrity and availability (C:H/I:H/A:H), consistent with an elevation-of-privilege outcome on the affected system. Any supported Windows system containing the Graphics Component is affected, and Microsoft addressed the flaw among the 973 vulnerabilities fixed in the September 2026 Patch Tuesday release. Exploitation has not been observed: the bug is not on CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates (Windows cumulative updates) to all supported Windows clients and servers, checking Microsoft's advisory for the exact KB/article numbers for each OS version. Prioritize endpoints where untrusted users can execute local code, such as shared workstations, VDI hosts and kiosks. With no public PoC or in-the-wild exploitation reported, standard patch-cycle urgency is adequate, but verify deployment rather than deferring past the next monthly cycle given the high local-impact rating.

Affected
Microsoft Graphics Component (shipped with Windows client and server editions)
Estimated exposure
mass≈1 billion+ Windows installations (the Graphics Component ships in-box with all supported Windows client and server versions) — The Graphics Component is an in-box Windows component, so the exposed population is effectively the entire supported Windows install base (over one billion active devices per Microsoft's published figures), though practical risk is highest…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs