Executive brief
A security vulnerability exists in the Windows component responsible for processing multimedia files. If a user is tricked into opening a specially crafted media file, an attacker could gain the ability to run unauthorized code on the victim's computer. This could lead to a full system compromise, data theft, or the installation of malicious software.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Microsoft Windows Media Foundation framework. The vulnerability is triggered when the component fails to properly validate or handle specific data within a media file, leading to memory corruption. While the attack vector is local, it requires user interaction (UI:R), typically involving a victim opening a malicious file or visiting a website hosting malicious media content. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory