Junglewise Threat Intelligence

CVE-2026-69467: Microsoft Graphics Component stack-based buffer overflow

CVE-2026-69467 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Graphics Component. Vendors: Microsoft.

Executive brief

Microsoft's Graphics Component contains a stack-based buffer overflow vulnerability that allows an authorized local attacker to elevate their privileges on a Windows system. Successful exploitation could allow an attacker with standard user access to gain system-level control, potentially compromising the confidentiality and integrity of an entire machine and its data.

Technical details

A stack-based buffer overflow exists in the Microsoft Graphics Component, triggered when processing specially crafted input. The vulnerability requires local access and an existing authorized account on the system. An attacker with local user privileges can craft malicious input to overflow a stack buffer, overwrite the return pointer, and achieve arbitrary code execution with elevated privileges. The attack is not remotely exploitable and requires an existing local account. Patches are expected to be available from Microsoft Security Response Center.

Affected products

  • Microsoft Graphics Component

Timeline

  • 2026-09-08: disclosed

References

Related threats