Junglewise Threat Intelligence

CVE-2026-57090: Microsoft Windows Media Foundation heap overflow

CVE-2026-57090 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Windows Media Foundation, a component used by the operating system to process multimedia files and streams. An attacker could exploit this flaw to take control of a user's computer if the user is tricked into opening a specially crafted file or visiting a malicious website. This could lead to unauthorized access to sensitive data, system instability, or the installation of malicious software.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Windows Media Foundation. The flaw is triggered when the component improperly handles specially crafted multimedia content, leading to memory corruption. While the attack vector is network-based, it requires user interaction (UI:R), such as a user opening a malicious file or navigating to a compromised webpage. Successful exploitation allows an unauthenticated attacker to achieve remote code execution (RCE) in the context of the current user. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 Standard and Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats