Impact
The vulnerability is a heap-based buffer overflow in the Microsoft Windows Codecs Library that can be triggered by an attacker who sends specially crafted media data to the Web Media Extensions component. This overflow enables an attacker to execute arbitrary code on the affected system, resulting in full compromise of confidentiality, integrity, and availability.
Affected Systems
Microsoft Web Media Extensions is the affected component. The advisory does not list specific version ranges; as a result, all supported releases of this component are considered vulnerable until a security update is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the exploit is feasible over a network connection to the Web Media Extensions service, making it a likely target for attackers, especially when the affected software is exposed to untrusted traffic. Because the flaw is a buffer overflow, bypassing normal input validation, the risk of successful exploitation remains high.
OpenCVE Enrichment