Impact
A memory corruption flaw in Windows Direct Show, classified as an out‑of‑bounds read (CWE‑125) and a buffer overflow (CWE‑122), allows an attacker with network access to read beyond a buffer and potentially corrupt memory, leading to arbitrary code execution in the context of the process that loads media streams.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is network‑based, wherein an attacker delivers a crafted media stream or file to the target system’s Direct Show services, enabling remote code execution. Consequently, the risk is high for any machine that exposes Direct Show to untrusted traffic.
OpenCVE Enrichment