• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54984: heap buffer overflow in Microsoft Windows 10 Version 1607

A local attacker can execute arbitrary code on affected Windows installations via a heap-based buffer overflow in the Windows Imaging Component (CVE-2026-54984). Multiple Windows 10, Windows 11 and Windows Server 2012 branches are affected; affected builds include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9418) and other listed build ranges. The vulnerability requires local access and user interaction to trigger, and fixes are available in the vendor-supplied builds.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00466
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize installing the vendor fixes for impacted builds or restrict local exposure immediately.

What is CVE-2026-54984?

A local attacker can execute arbitrary code on affected Windows installations via a heap-based buffer overflow in the Windows Imaging Component (CVE-2026-54984). Multiple Windows 10, Windows 11 and Windows Server 2012 branches are affected; affected builds include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9418) and other listed build ranges. The vulnerability requires local access and user interaction to trigger, and fixes are available in the vendor-supplied builds. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.766310.0.19044.7663
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.766310.0.19045.7663
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.916810.0.26100.9168
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.916810.0.26200.9168
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.270410.0.28000.2704
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280

Is CVE-2026-54984 being exploited?

Public exploit code is available.

How to fix CVE-2026-54984

  1. Install the Microsoft updates that include the fixed builds (for example 10.0.14393.9418 for Windows 10 Version 1607 and the corresponding fixed builds for other branches).
  2. If you cannot yet patch, restrict local access to affected systems and limit who can open untrusted images or files.
  3. Monitor endpoints for suspicious activity and review logs for signs of code execution or anomalous process launches.
  4. Follow Microsoft guidance for deploying the updates and validating successful installation.

Frequently asked questions

Is CVE-2026-54984 being actively exploited?

Public exploit code for CVE-2026-54984 is available.

Which Windows 10 Version 1607 versions are affected by CVE-2026-54984?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9418 are affected; the issue is fixed in build 10.0.14393.9418.

Is there a patch for CVE-2026-54984?

Yes. Microsoft published updates that include fixed builds such as 10.0.14393.9418 for Windows 10 Version 1607 and corresponding fixed builds for other affected branches.

Does CVE-2026-54984 require authentication?

No prior account privileges are required, but the flaw requires local access and user interaction to trigger on affected Windows systems.

References