Description
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in the Microsoft Windows Codecs Library that can be triggered by an attacker who sends specially crafted media data to the Web Media Extensions component. This overflow enables an attacker to execute arbitrary code on the affected system, resulting in full compromise of confidentiality, integrity, and availability.

Affected Systems

Microsoft Web Media Extensions is the affected component. The advisory does not list specific version ranges; as a result, all supported releases of this component are considered vulnerable until a security update is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the exploit is feasible over a network connection to the Web Media Extensions service, making it a likely target for attackers, especially when the affected software is exposed to untrusted traffic. Because the flaw is a buffer overflow, bypassing normal input validation, the risk of successful exploitation remains high.

Generated by OpenCVE AI on September 9, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update released by Microsoft for Web Media Extensions.
  • Disable or uninstall the Web Media Extensions component if it is not required for business operations.
  • Configure network and application firewalls to block or restrict traffic that could deliver malicious media to the vulnerable component.
  • Monitor system logs for signs of buffer overflow attempts or unexpected process behavior.

Generated by OpenCVE AI on September 9, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
Title Web Media Extensions Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft web Media Extensions
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:web_media_extensions:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft web Media Extensions
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Web Media Extensions Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:35.719Z

Reserved: 2026-08-26T18:40:19.856Z

Link: CVE-2026-81352

cve-icon Vulnrichment

Updated: 2026-09-09T09:52:52.804Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:52.940

Modified: 2026-09-23T15:39:40.480

Link: CVE-2026-81352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T00:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow