Description
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap‑based buffer overflow exists in the Microsoft Windows Codecs Library that is triggered by processing HEIF image files. The flaw allows an attacker with no prior access to the system to execute arbitrary code locally. An exploit would enable the attacker to run code with the privileges of the user who opened the corrupted HEIF image, potentially compromising the integrity of the system or allowing further privilege escalation.

Affected Systems

The Microsoft HEIF Image Extension is affected. All deployed instances of this extension may be vulnerable, regardless of the host application or the version of Windows, because no specific version range is supplied. The vulnerability exists in any environment where HEIF images are processed by the extension.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity, indicating a significant impact if successfully exploited. The EPSS score is unavailable, giving no guidance on current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed large‑scale exploitation yet. The likely attack vector is local, based on an attacker creating or modifying a HEIF file that is then opened by a user or application. Successful exploitation would grant code execution with the current user’s privileges, potentially allowing the attacker to install malware or modify system data.

Generated by OpenCVE AI on September 9, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest update for the HEIF Image Extension through Windows Update or Microsoft Update Catalog.
  • If no update is available, uninstall the HEIF Image Extension to remove the vulnerable component from the system.
  • Disable automatic loading of HEIF images in applications that rely on the extension until a patch is released.

Generated by OpenCVE AI on September 9, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Title HEIF Image Extensions Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft heif Image Extension
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:heif_image_extension:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft heif Image Extension
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Heif Image Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:36.239Z

Reserved: 2026-08-26T18:40:19.856Z

Link: CVE-2026-81353

cve-icon Vulnrichment

Updated: 2026-09-10T20:56:12.155Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:53.070

Modified: 2026-09-17T19:03:59.360

Link: CVE-2026-81353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T02:45:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow