Executive brief
A security vulnerability exists in the Microsoft Windows Codecs Library, which is responsible for processing various image and video formats. An attacker who successfully exploits this flaw could gain access to sensitive information stored in the computer's memory. To carry out the attack, a user would typically need to be tricked into opening a specially crafted file or visiting a malicious website.
Technical details
A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in the Microsoft Windows Codecs Library. The flaw occurs when the library fails to properly initialize memory buffers before use, potentially allowing a local attacker to read sensitive data from the system's memory. The attack vector is local, but it requires user interaction, such as a user opening a malicious file that triggers the vulnerable codec. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD