Impact
A heap-based buffer overflow in the Windows Media component allows an authorized attacker to execute code locally. The flaw occurs when processing media data triggers a heap overflow, allowing the attacker to execute arbitrary code on the system.
Affected Systems
Affected systems include Microsoft Windows 11 versions 24H2, 25H2, and 26H1 as well as Windows Server 2025 and its Server Core installation. The vulnerability applies to both arm64 and x64 builds as listed in the CPE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk for the affected products. The EPSS score of less than 1% reflects an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying that active exploitation is not yet reported. Exploitation requires local or authenticated access to the system and involves delivering malicious media data that triggers a heap‑based buffer overflow in the Windows Media component.
OpenCVE Enrichment