CVE-2026-70296 – Windows Imaging Component Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A malicious RAW image can turn a routine Windows preview into remote code execution, without requiring privileges or user interaction.”
CVE-2026-70296 is a critical remote code execution vulnerability in the Windows Imaging Component caused by an out-of-bounds write. An attacker can craft a malicious RAW image and convince a user to navigate to a folder containing it. Windows can trigger the vulnerability while generating the image thumbnail or preview, meaning the file does not need to be opened. Successful exploitation can allow unauthorized code execution over a network.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-787
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.