Junglewise Threat Intelligence

CVE-2026-73013: Microsoft Windows Imaging Component heap buffer overflow

CVE-2026-73013 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Imaging Component is a core library in Windows used to process and render images in various formats. A heap-based buffer overflow in this component allows a remote attacker to execute arbitrary code on a user's system over the network, potentially leading to complete system compromise.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Windows Imaging Component, allowing remote code execution. The vulnerability can be exploited over the network without requiring user authentication or interaction, making it a critical network-reachable attack vector. An attacker can craft malicious image data that, when processed by the component, triggers the buffer overflow and achieves arbitrary code execution with the privileges of the process handling the image. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Imaging Component

Timeline

  • 2026-09-08: disclosed

References

Related threats