Impact
A heap‑based buffer overflow exists in Windows Media Foundation. Based on the description, it is inferred that the flaw can be triggered by malicious media files processed by a local user, allowing attackers to execute arbitrary code with the user's privileges. The flaw is identified as CWE‑122, which involves unsafe handling of memory leading to buffer overflows.
Affected Systems
Microsoft Windows 10 (v16.07, v18.09, v21.02, v22.02), Windows 11 (v24.02, v25.02, v26.01), and Windows Server editions including 2012, 2012 R2, 2016, 2019, 2022, and 2025 along with their Server Core installations are affected.
Risk and Exploitability
The CVSS base score of 7.8 reflects high severity, but the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability has not been reported in the CISA KEV catalog, so there is no evidence of active exploitation. Based on the description, it is inferred that the likely attack path requires an attacker to create a malicious media file and trick a local or network‑shared user into opening it; no remote network component is needed for exploitation.
OpenCVE Enrichment