Impact
An integer overflow or wraparound in the Microsoft WebP Image Extension subverts normal memory bounds and permits an attacker who can deliver a crafted image to execute arbitrary code. The flaw is rooted in improper bounds checking, reflected in CWE-122 and CWE-190, and enables remote code execution when the extension processes images from an attacker-controlled source.
Affected Systems
Microsoft WebP Image Extension is the affected component. Specific version information is not supplied by the current advisory, so all deployed instances of the extension are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the exploit likelihood is not quantified by EPSS, though the vulnerability is not yet listed in the CISA KEV catalog. Because the flaw is triggered via a network‑based image delivery, attackers with network access can send malicious data to the victim. No public workarounds are documented, so protection must rely on updating the extension.
OpenCVE Enrichment