Impact
The vulnerability is a heap‑based buffer overflow in the Microsoft Windows Codecs Library used by the HEVC Video Extensions. An attacker can trigger the overflow with crafted HEVC media or by manipulating the codec’s API from a local process, allowing the execution of arbitrary code and a rise in privilege level on the affected machine. Because the flaw lies in memory handling, an exploit can yield full control of the system if the attacker can gain initial process access.
Affected Systems
Microsoft HEVC Video Extensions, Microsoft HEVC Video Extensions for Licensed Applications, and Microsoft HEVC Video Extensions from Device Manufacturer are affected. The CVE does not specify vulnerable releases, meaning any version that includes the unpatched Windows Codecs Library is at risk. Users should verify that their installation of these extensions uses the latest updates from Microsoft.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of analysis. The likely attack vector is local; an attacker must have the ability to run code on the victim or supply malicious media that the system processes. Successful exploitation results in privilege escalation, allowing the attacker to compromise the local user’s session or gain administrative privileges, potentially leading to data theft, persistence, or further lateral movement.
OpenCVE Enrichment