Impact
A heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. This flaw occurs when the framework processes a crafted media file, with unchecked heap allocations corrupting memory and enabling execution of arbitrary code. The vulnerability is classified as CWE‑122, a classic example of insufficient bounds checking in heap memory management.
Affected Systems
The affected systems are Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2019 (including Server Core); and Windows Server 2022 and 2025 (including Server Core). These compose the range of operating systems overlapped by the CNA list. No other products or versions are listed as affected in the current data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1 %, implying that exploitation is currently unlikely. The description explicitly states local code execution, thus the attack vector is local and requires the adversary to run a malicious media file or otherwise invoke Media Foundation. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of widespread active exploitation, though the high CVSS suggests that if a local attacker gains a foothold, they could fully compromise the affected machine.
OpenCVE Enrichment