Impact
The flaw is a heap-based buffer overflow in the Windows DirectMusic component. An attacker who can send specially crafted data to DirectMusic over a network can trigger the overflow and execute arbitrary code with the privileges of the DirectMusic process. This allows an attacker to compromise data confidentiality, integrity, and availability on the affected system.
Affected Systems
Affected products include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. All architectures listed in the CNAs are impacted.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog, but the lack of public exploitation data does not reduce the inherent risk. The likely attack vector involves network traffic directed at the DirectMusic service; thus, any system exposed to that traffic could be compromised. The vulnerability requires no user interaction beyond the delivery of malicious data over the network, and no local privilege escalation is needed to take advantage of it.
OpenCVE Enrichment