Impact
The flaw is a heap‑based buffer overflow in Windows Media Foundation. By sending crafted media data over a network connection, an attacker can trigger the overflow and execute arbitrary code. This gives the attacker full control of the application process and can lead to remote code execution with the privileges of that process.
Affected Systems
Affected versions include Microsoft Windows 10 (builds 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (builds 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server from 2012 through 2025, including both standard and core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability, and the spec notes that an unauthorized attacker can execute code over a network. While the EPSS score is not available, the lack of KEV listing suggests no public exploit yet. Nonetheless, the vulnerability is exploitable remotely if the target system has an active Media Foundation instance exposed to untrusted media data. The creator notes the flaw requires a network‑based request, which is a typical non‑authenticated remote code execution scenario. Organizations should treat this as a high risk until the patch is applied.
OpenCVE Enrichment