Impact
Heap-based buffer overflow vulnerability in the Windows Codecs Library allows an attacker with local access to execute arbitrary code, compromising confidentiality, integrity, and system availability. The attack exploits a flaw classified as CWE-122, enabling overwrite of heap control data that can be leveraged to gain execution privileges. The affected component is the HEVC Video Extensions codec provided by Microsoft.
Affected Systems
Microsoft HEVC Video Extensions, including the standard, licensed application, and device manufacturer distributions, are impacted. No specific product version is listed in the advisory, so all releases linked to the Microsoft HEVC Video Extensions package are potentially vulnerable.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability represents a high‑severity local code‑execution risk. EPSS data is not available, making the current exploit probability uncertain; the issue is not yet listed in CISA’s KEV catalog. Attacks would require the attacker to supply crafted HEVC data on a machine that has the codec installed, so risk is confined to environments that use this codec for local media decoding.
OpenCVE Enrichment