Description
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

An integer overflow or wraparound in the Microsoft WebP Image Extension subverts normal memory bounds and permits an attacker who can deliver a crafted image to execute arbitrary code. The flaw is rooted in improper bounds checking, reflected in CWE-122 and CWE-190, and enables remote code execution when the extension processes images from an attacker-controlled source.

Affected Systems

Microsoft WebP Image Extension is the affected component. Specific version information is not supplied by the current advisory, so all deployed instances of the extension are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the exploit likelihood is not quantified by EPSS, though the vulnerability is not yet listed in the CISA KEV catalog. Because the flaw is triggered via a network‑based image delivery, attackers with network access can send malicious data to the victim. No public workarounds are documented, so protection must rely on updating the extension.

Generated by OpenCVE AI on September 10, 2026 at 00:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft WebP Image Extension update that addresses the integer overflow issue.
  • If the extension is not required, disable or uninstall it from affected systems.
  • Restrict network traffic to the services that expose the extension using firewalls or network segmentation to limit attacker reach.

Generated by OpenCVE AI on September 10, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
Title Microsoft WebP Image Extension Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft webp Image Extension
Weaknesses CWE-122
CWE-190
CPEs cpe:2.3:a:microsoft:webp_image_extension:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft webp Image Extension
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Webp Image Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:16.842Z

Reserved: 2026-08-04T00:04:56.037Z

Link: CVE-2026-70351

cve-icon Vulnrichment

Updated: 2026-09-09T18:19:18.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:20:08.237

Modified: 2026-09-09T19:17:43.277

Link: CVE-2026-70351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T00:15:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound