Junglewise Threat Intelligence

CVE-2026-84000: Microsoft Graphics Component heap-based buffer overflow

CVE-2026-84000 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft's Graphics Component contains a flaw that can be exploited by an authorized user on a computer to run malicious code with elevated privileges. This could allow an attacker with local access to take control of the system, access sensitive data, or disrupt business operations.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Graphics Component. The vulnerability requires local network access and authenticated user privileges to exploit. An attacker can trigger the overflow by sending specially crafted input to the Graphics Component, allowing arbitrary code execution in the context of the affected process. A fix is expected to be available through Microsoft security updates; systems should be patched as soon as updates are released.

Affected products

  • Microsoft Graphics Component

Timeline

  • 2026-09-08: disclosed

References

Related threats