Executive brief
A security vulnerability has been identified in Windows Media, a core component of the Windows operating system used for playing audio and video files. If an attacker successfully tricks a user into opening a specially crafted file, they could gain the ability to run malicious code on the user's computer. This could lead to a full system compromise, including the theft of sensitive data or the installation of unauthorized software.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows Media component across multiple versions of Windows and Windows Server. The vulnerability is triggered when the system processes a specially crafted media file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file (User Interaction required), resulting in arbitrary code execution in the context of the current user. The attack vector is local, and Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory