Executive brief
Windows Paint is a basic graphics editing application included with Windows. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code remotely, potentially compromising a user's system and enabling unauthorized access to data or system control.
Technical details
The vulnerability is a heap-based buffer overflow in Windows Paint's image processing routines. The flaw can be triggered remotely when processing specially crafted image files, without requiring user authentication. An attacker can exploit this to achieve remote code execution with the privileges of the Paint application, leading to full system compromise if the user has administrative rights.
Affected products
- Microsoft Windows Paint
Timeline
- 2026-09-08: disclosed