CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Other sources
Windows Imaging Component Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is network-reachable and does not require attacker privileges, but it does require user interaction. Successful exploitation could allow code execution with high impact to confidentiality, integrity, and availability.
What is known about affected versions or configurations?
The available data identifies Microsoft Windows Imaging Component but does not specify affected Windows versions, component versions, or whether default configurations are affected.
How can I determine whether systems are already compromised or whether a workaround is available?
The provided information does not include indicators of compromise, detection guidance, mitigations, or workarounds. Review the vendor advisory for remediation and investigation details.