Executive brief
A security vulnerability exists in the Windows component responsible for processing multimedia files. An attacker could exploit this by tricking a user into opening a specially crafted file or visiting a malicious website, potentially allowing the attacker to take full control of the computer. This could lead to the theft of sensitive data, installation of malware, or disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Windows Media Foundation. The vulnerability is triggered when the component improperly handles specially crafted multimedia content. An unauthenticated remote attacker can exploit this by inducing a user to interact with malicious content (User Interaction: Required), such as opening a file or navigating to a compromised webpage. Successful exploitation allows for remote code execution (RCE) in the context of the current user. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory