8.8
CVE-2026-81955
- EPSS 0.6%
- Veröffentlicht 08.09.2026 17:19:05
- Zuletzt bearbeitet 24.09.2026 23:19:14
- Erkennungen
Windows Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMicrosoft
≫
Produkt
Microsoft 365 Apps for Enterprise
Version
16.0.1
Version <
16.0.20326.20138
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office 2016
Version
16.0.0
Version <
16.0.5569.1003
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office 2019
Version
19.0.0
Version <
16.0.10417.20207
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office 365 for Mac
Version
1.0.0
Version <
16.113.26091433
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC 2021
Version
16.0.1
Version <
16.0.14334.20906
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC 2024
Version
16.0.0
Version <
16.0.17932.20976
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC for Mac 2021
Version
16.0.1
Version <
16.113.26091433
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC for Mac 2024
Version
16.0.0
Version <
16.113.26091433
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 10 Version 1607
Version
10.0.14393.0
Version <
10.0.14393.9504
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 10 Version 1809
Version
10.0.17763.0
Version <
10.0.17763.9245
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 10 Version 21H2
Version
10.0.19044.0
Version <
10.0.19044.7725
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 10 Version 22H2
Version
10.0.19045.0
Version <
10.0.19045.7725
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 11 version 23H2
Version
10.0.22631.0
Version <
10.0.22631.7582
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 11 Version 23H2
Version
10.0.22631.0
Version <
10.0.22631.7582
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 11 Version 24H2
Version
10.0.26100.0
Version <
10.0.26100.9445
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 11 Version 25H2
Version
10.0.26200.0
Version <
10.0.26200.9445
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows 11 version 26H1
Version
10.0.28000.0
Version <
10.0.28000.2954
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2012
Version
6.2.9200.0
Version <
6.2.9200.26349
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2012 (Server Core installation)
Version
6.2.9200.0
Version <
6.2.9200.26349
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2012 R2
Version
6.3.9600.0
Version <
6.3.9600.23398
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2012 R2 (Server Core installation)
Version
6.3.9600.0
Version <
6.3.9600.23398
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2016
Version
10.0.14393.0
Version <
10.0.14393.9504
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2016 (Server Core installation)
Version
10.0.14393.0
Version <
10.0.14393.9504
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2019
Version
10.0.17763.0
Version <
10.0.17763.9245
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2019 (Server Core installation)
Version
10.0.17763.0
Version <
10.0.17763.9245
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2022
Version
10.0.20348.0
Version <
10.0.20348.5622
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2025
Version
10.0.26100.0
Version <
10.0.26100.33438
Status
affected
HerstellerMicrosoft
≫
Produkt
Windows Server 2025 (Server Core installation)
Version
10.0.26100.0
Version <
10.0.26100.33438
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.466 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81955