Impact
A heap‑based buffer overflow exists in Microsoft Windows Media Foundation that allows an unauthorized attacker to execute code. The vulnerability is a classic buffer overflow (CWE‑122) that can be triggered over a network, resulting in remote code execution on the affected host.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% shows that exploitation is currently uncommon. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a network‑based attacker delivering a crafted media file or stream to the vulnerable component.
OpenCVE Enrichment