Junglewise Threat Intelligence

CVE-2026-73023: Microsoft Windows Imaging Component heap overflow

CVE-2026-73023 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Imaging Component is a core Windows system library used to process and manipulate image files. A heap-based buffer overflow in this component allows a remote attacker to execute arbitrary code on a vulnerable system, potentially compromising the entire computer and enabling theft of sensitive data or deployment of malware.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Imaging Component, a library responsible for image processing in Windows. The vulnerability can be triggered remotely when a user opens a specially crafted image file, allowing an attacker to overwrite heap memory and achieve arbitrary code execution with the privileges of the affected user. No authentication is required to exploit this vulnerability; a network-accessible attack vector enables exploitation through malicious image files delivered via email, web browsers, or other means. While not currently exploited in the wild at time of disclosure, patches are available from Microsoft.

Affected products

  • Microsoft Windows Imaging Component

Timeline

  • 2026-09-08: disclosed

References

Related threats