Impact
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. The flaw arises when the Media Foundation component processes malformed media data, allowing the attacker to corrupt memory and execute injected code. This vulnerability permits complete compromise of the affected machine, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over the network via the Media Foundation service. If successfully exploited, an attacker gains full control of the target system and may install malware, steal data, or pivot to other network resources. The low EPSS suggests that, although the impact is severe, exploitation in the wild is expected to be uncommon until an exploit becomes publicly available.
OpenCVE Enrichment