Impact
A heap‑based buffer overflow exists in Microsoft Windows Media Foundation. The flaw, classified as CWE‑122, permits an unauthenticated attacker to supply crafted data over a network and execute arbitrary code with system privileges, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. These releases contain Media Foundation components vulnerable to the described overflow; the specific build identifiers are not listed but the CPE entries confirm the affected architecture variants.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS data is unavailable, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers could exploit the flaw remotely by transmitting malicious packets that target the Media Foundation pipeline, leveraging network access. The absence of a public exploit reference suggests that the risk is theoretical at present, but the high CVSS justifies a proactive response.
OpenCVE Enrichment