Executive brief
A security vulnerability exists in the Windows component responsible for processing multimedia files like audio and video. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the computer. This could lead to a full system compromise, allowing the attacker to steal data or install malware.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Microsoft Windows Media Foundation framework. The vulnerability is triggered when the component improperly handles specially crafted media content. An attacker can exploit this by convincing a local user to open a malicious file or visit a malicious website that hosts such content. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack requires user interaction (UI:R) but no prior privileges (PR:N). Microsoft has released security updates to address this issue across various Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory