Executive brief
A security vulnerability has been identified in Windows Media, a core component of the Windows operating system used for playing audio and video files. If a user is tricked into opening a specially crafted malicious media file, an attacker could gain the ability to run unauthorized code on the victim's computer. This could lead to a full system compromise, allowing the attacker to steal data, install malware, or disrupt operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows Media component across multiple versions of Windows 11 and Windows Server 2025. The vulnerability is triggered when the system processes a malformed media file. While the attack vector is local, it requires user interaction (UI:R), typically involving a user opening a malicious file provided by the attacker. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user. Microsoft has released security updates to address this issue; administrators should verify build versions against the MSRC update guide.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft