Impact
A heap‑based buffer overflow exists in the Microsoft Windows Codecs Library that is triggered by processing HEIF image files. The flaw allows an attacker with no prior access to the system to execute arbitrary code locally. An exploit would enable the attacker to run code with the privileges of the user who opened the corrupted HEIF image, potentially compromising the integrity of the system or allowing further privilege escalation.
Affected Systems
The Microsoft HEIF Image Extension is affected. All deployed instances of this extension may be vulnerable, regardless of the host application or the version of Windows, because no specific version range is supplied. The vulnerability exists in any environment where HEIF images are processed by the extension.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, indicating a significant impact if successfully exploited. The EPSS score is unavailable, giving no guidance on current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed large‑scale exploitation yet. The likely attack vector is local, based on an attacker creating or modifying a HEIF file that is then opened by a user or application. Successful exploitation would grant code execution with the current user’s privileges, potentially allowing the attacker to install malware or modify system data.
OpenCVE Enrichment