Executive brief
A security vulnerability has been identified in Windows Media components that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file or visiting a malicious website. If successful, the attacker could execute unauthorized commands, potentially leading to data theft or full system compromise.
Technical details
A heap-based buffer overflow (CWE-122) exists in Windows Media components. The vulnerability is triggered when the system processes a specially crafted file, leading to memory corruption. While classified as a local attack vector, it requires user interaction (UI:R), such as opening a malicious media file. Successful exploitation allows for arbitrary code execution in the context of the logged-in user. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Versions 1809, 21H2, 22H2 (prior to specific build updates)
- Microsoft Windows 11 Versions 22H3, 23H2, 24H2, 25H2 (prior to specific build updates)
- Microsoft Windows Server 2019 Prior to build 10.0.17763.8276
- Microsoft Windows Server 2022 Affected
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory