Impact
A vulnerability in Microsoft Windows Media Foundation can be triggered by an unauthorized user with network access, allowing the execution of arbitrary code on the affected system. The flaw is an out‑of‑bounds read (CWE‑125) that can be leveraged to gain remote code execution privileges, potentially leading to a stack‑based buffer overflow (CWE‑121). According to the official description, the impact is the ability to execute code remotely, which can compromise confidentiality, integrity, and availability of the host.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, Server 2025, including their server‑core installations. The vulnerability applies to all listed editions and architectures (x86, x64, arm64).
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is network‑based; an attacker could deliver a crafted media file or packet that exploits the Media Foundation component while it is processing the input. The described out‑of‑bounds read condition can lead to remote code execution if successfully triggered.
OpenCVE Enrichment