Impact
A heap-based buffer overflow exists in the Windows Media component, enabling an attacker to influence the program’s memory management, which can lead to code execution with the privileges of the user running Windows Media. The description does not indicate privilege escalation beyond the local user context.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including Server Core). Version 24H2 and 25H2 are available for arm64, 26H1 for x64, and the Server 2025 releases support both architectures.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of < 1 % suggests a low likelihood of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would involve an attacker delivering a crafted media file to a user who opens it through Windows Media Player or a related service, triggering the heap overflow and resulting in local code execution.
OpenCVE Enrichment