Impact
The flaw is a heap‑based buffer overflow in Windows Media Foundation that permits an unauthorized attacker to execute arbitrary code remotely. The overflow occurs when the application processes crafted data, resulting in a potential compromise of the affected system.
Affected Systems
Microsoft products affected include Windows 10 build 1607, 1809, 21H2 and 22H2; Windows 11 build 23H2, 24H2, 25H2 and 26H1; and several Windows Server releases – Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022 and Server 2025 – in both standard and Server Core installations.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity. EPSS is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability can be triggered by an attacker sending specially crafted multimedia data over the network to the Media Foundation component, implying a network‑based attack vector. The impact is complete loss of confidentiality, integrity, and availability for the compromised host.
OpenCVE Enrichment