Impact
A heap‑based buffer overflow exists in the Microsoft Windows Media Foundation component, allowing an attacker to corrupt adjacent heap memory by sending malformed media data over a network. When triggered, this flaw can result in arbitrary code execution with the privileges of the Media Foundation service, giving the attacker complete control of the target machine.
Affected Systems
Affected products are Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including default and Server Core installations. These versions contain the unpatched Media Foundation component.
Risk and Exploitability
The CVSS score of 8.8 marks this flaw as high severity. The EPSS score is not available, so the probability of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog. Likely the attack vector is a remote network connection feeding malicious media streams to Media Foundation; the flaw requires an unauthenticated attacker to craft and send the payload, and will execute code on the target system. Precise exploitation is described only in the description, so the risk is that an attacker could take full control of the target machine.
OpenCVE Enrichment