Description
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in the Microsoft Windows Codecs Library used by the HEVC Video Extensions. An attacker can trigger the overflow with crafted HEVC media or by manipulating the codec’s API from a local process, allowing the execution of arbitrary code and a rise in privilege level on the affected machine. Because the flaw lies in memory handling, an exploit can yield full control of the system if the attacker can gain initial process access.

Affected Systems

Microsoft HEVC Video Extensions, Microsoft HEVC Video Extensions for Licensed Applications, and Microsoft HEVC Video Extensions from Device Manufacturer are affected. The CVE does not specify vulnerable releases, meaning any version that includes the unpatched Windows Codecs Library is at risk. Users should verify that their installation of these extensions uses the latest updates from Microsoft.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of analysis. The likely attack vector is local; an attacker must have the ability to run code on the victim or supply malicious media that the system processes. Successful exploitation results in privilege escalation, allowing the attacker to compromise the local user’s session or gain administrative privileges, potentially leading to data theft, persistence, or further lateral movement.

Generated by OpenCVE AI on September 8, 2026 at 18:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft HEVC Video Extensions to the latest version provided by Microsoft.
  • If the extension is not required, uninstall or disable it from Windows settings to eliminate the vulnerable code path.
  • As an interim measure, apply application control policies to block execution of the HEVC codecs library until a security update is installed.

Generated by OpenCVE AI on September 8, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
Title HEVC Video Extensions Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft hevc Video Extensions
Microsoft hevc Video Extensions For Licensed Appplications
Microsoft hevc Video Extensions From Device Manufacturer
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:hevc_video_extensions:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:hevc_video_extensions_for_licensed_appplications:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:hevc_video_extensions_from_device_manufacturer:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft hevc Video Extensions
Microsoft hevc Video Extensions For Licensed Appplications
Microsoft hevc Video Extensions From Device Manufacturer
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Hevc Video Extensions Hevc Video Extensions For Licensed Appplications Hevc Video Extensions From Device Manufacturer
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:32:31.584Z

Reserved: 2026-07-01T18:03:43.124Z

Link: CVE-2026-58600

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:43.923

Modified: 2026-09-08T18:39:13.460

Link: CVE-2026-58600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow