Impact
This vulnerability is caused by an integer overflow or wraparound in Microsoft Windows Media Foundation that lets an attacker launch arbitrary code on the targeted system. The flaw allows a remote actor to inject malicious data into the media processing pipeline, leading to execution of arbitrary code with the privileges of the current user. Consequently, all aspects of confidentiality, integrity, and availability can be compromised, enabling attackers to install malware, steal data, or pivot to other systems.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2 through 26H1; as well as Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. These versions are affected regardless of architecture except for the specific builds noted in the CPE list.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as Critical, and the lack of a publicly available EPSS score means actual exploitation frequency is unknown but the potential impact is high. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploits have yet been catalogued. The likely attack vector is over a network when a malicious media file is processed by Media Foundation – an attacker can trigger the overflow by sending crafted media over protocols such as HTTP, SMB, or other channels that allow media input.
OpenCVE Enrichment