Junglewise Threat Intelligence

CVE-2026-70296: Microsoft Windows Imaging Component out-of-bounds write

CVE-2026-70296 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Imaging Component is a system library used by Windows and applications to process image files. An attacker can exploit an out-of-bounds write vulnerability in this component to execute arbitrary code remotely, potentially compromising an entire system without user interaction. This poses a critical risk to all Windows users.

Technical details

An out-of-bounds write vulnerability exists in Microsoft's Windows Imaging Component, a core library responsible for parsing and processing image file formats. The vulnerability allows a network-based attacker to trigger the flaw by sending a specially crafted image file, potentially without requiring authentication or user interaction. Successful exploitation results in arbitrary code execution with the privileges of the affected application or system process. The high CVSS score (9.8) reflects the low complexity of exploitation and network attack vector combined with the severe impact of remote code execution.

Affected products

  • Microsoft Windows Imaging Component

Timeline

  • 2026-09-08: disclosed

References

Related threats