Impact
The vulnerability is a missing required padding in the WMA extradata allocation code path of FFmpeg prior to version 9.0, leading to an out‑of‑bounds read. This flaw enables an attacker to read data beyond the allocated buffer, potentially exposing confidential information from memory. The weakness is classified as CWE‑125: Out‑of‑Bounds Read.
Affected Systems
FFmpeg, all releases before 9.0 that use the WMA codec. The flaw resides in libavcodec/wmaenc.c and affects any system that decodes or encodes WMA media streams with FFmpeg.
Risk and Exploitability
The CVSS base score is 2.9, indicating low severity. The EPSS score is less than 1%, reflecting an extremely low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting a limited attack window. Exploitation likely requires a crafted WMA file or code execution within a media processing environment, meaning the attack vector is either local or requires the target to process malicious media.
OpenCVE Enrichment