Description
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. This flaw occurs when the framework processes a crafted media file, with unchecked heap allocations corrupting memory and enabling execution of arbitrary code. The vulnerability is classified as CWE‑122, a classic example of insufficient bounds checking in heap memory management.

Affected Systems

The affected systems are Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2019 (including Server Core); and Windows Server 2022 and 2025 (including Server Core). These compose the range of operating systems overlapped by the CNA list. No other products or versions are listed as affected in the current data.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1 %, implying that exploitation is currently unlikely. The description explicitly states local code execution, thus the attack vector is local and requires the adversary to run a malicious media file or otherwise invoke Media Foundation. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of widespread active exploitation, though the high CVSS suggests that if a local attacker gains a foothold, they could fully compromise the affected machine.

Generated by OpenCVE AI on July 31, 2026 at 09:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft patch for CVE-2026-54993 via Windows Update or the MSRC update guide.
  • If a patch is not yet released, disable Windows Media Foundation components or restrict access to media files that trigger the vulnerable code path.
  • Enforce least privilege for local accounts that run media applications and limit the ability to execute arbitrary media content.

Generated by OpenCVE AI on July 31, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
Title Microsoft Windows Media Foundation Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:28.696Z

Reserved: 2026-06-16T14:10:05.869Z

Link: CVE-2026-54993

cve-icon Vulnrichment

Updated: 2026-07-15T10:58:44.791Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow