Executive brief
Microsoft's Graphics Component, a core Windows library used for rendering and displaying images and graphics, contains a heap-based buffer overflow vulnerability. An attacker could exploit this flaw over the network without requiring authentication to execute arbitrary code with system-level privileges, potentially compromising the entire system.
Technical details
A heap-based buffer overflow exists in Microsoft Graphics Component that can be triggered remotely without authentication. The vulnerability allows an attacker to corrupt heap memory and achieve remote code execution (RCE) over the network. The vulnerability is not known to be exploited in the wild as of the publication date, but patches should be applied immediately given the high attack surface and critical nature of the Graphics Component.
Affected products
- Microsoft Graphics Component
Timeline
- 2026-09-08: disclosed