Impact
The heap-based buffer overflow occurs in the Microsoft Windows Media Foundation component, allowing an attacker to trigger memory corruption by sending crafted media data. Once the overflow is exploited, the attacker can achieve arbitrary code execution with the privileges of the calling process. This can compromise system confidentiality, integrity, and availability. The weakness is identified as CWE-122 (heap-based buffer overflow).
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (24H2, 25H2, 26H1) on x86, x64, and arm64 architectures, as well as Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations are all affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack that requires an attacker to deliver specially crafted data to the Media Foundation component to trigger the overflow.
OpenCVE Enrichment