Impact
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally, potentially compromising the confidentiality and integrity of the target system. If an attacker can supply a specially crafted media file or otherwise trigger the overflow under the user’s privileges, the flaw may be leveraged for privilege escalation as well. The vulnerability is rooted in improper heap memory handling identified as CWE-122.
Affected Systems
Affected platforms include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, including Server Core installations. The flaw impacts 32‑bit (x86), 64‑bit (x64), and ARM64 versions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet the EPSS score of <1% suggests a very low likelihood of current exploitation. The vulnerability's attack vector is local; an attacker must gain local user access to deliver the malicious media file or trigger the overflow, making the flaw a local code execution risk.
OpenCVE Enrichment