Description
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap‑based buffer overflow exists in Microsoft Windows Media Foundation. The flaw, classified as CWE‑122, permits an unauthenticated attacker to supply crafted data over a network and execute arbitrary code with system privileges, compromising confidentiality, integrity, and availability of the affected machine.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. These releases contain Media Foundation components vulnerable to the described overflow; the specific build identifiers are not listed but the CPE entries confirm the affected architecture variants.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS data is unavailable, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers could exploit the flaw remotely by transmitting malicious packets that target the Media Foundation pipeline, leveraging network access. The absence of a public exploit reference suggests that the risk is theoretical at present, but the high CVSS justifies a proactive response.

Generated by OpenCVE AI on September 8, 2026 at 19:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE‑2026‑62744 on all Windows 11 and Windows Server 2025 systems.
  • Disable or limit the use of Media Foundation components that process external media input, such as turning off the Windows Media Player feature or restricting access to media service ports.
  • Monitor network traffic for anomalous activity involving Media Foundation or unexpected media streams, and apply additional network segmentation or firewall rules to prevent unauthorized access to media processing endpoints.

Generated by OpenCVE AI on September 8, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Title Microsoft Windows Media Foundation Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:13.309Z

Reserved: 2026-07-14T21:01:21.823Z

Link: CVE-2026-62744

cve-icon Vulnrichment

Updated: 2026-09-09T19:15:20.122Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:17:57.417

Modified: 2026-09-28T17:26:12.130

Link: CVE-2026-62744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:15:06Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow