Executive brief
Windows Imaging Component is a Microsoft system library that processes image files and formats. An integer overflow vulnerability in this component allows an attacker to execute arbitrary code on a system by sending a specially crafted image file over the network, potentially compromising the integrity and availability of affected systems.
Technical details
The vulnerability is an integer overflow or wraparound condition in Microsoft Windows Imaging Component that can be exploited to achieve remote code execution. The flaw is reachable over the network and does not require authentication or user interaction beyond processing a malicious image. An attacker can craft a specially formatted image file that triggers the integer overflow, leading to memory corruption and code execution with the privileges of the application processing the image. Patches are available from Microsoft.
Affected products
- Microsoft Windows Imaging Component
Timeline
- 2026-09-08: disclosed