Junglewise Threat Intelligence

CVE-2026-58599: Microsoft Windows Codecs Library heap-based buffer overflow

CVE-2026-58599 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

The Windows Codecs Library, a system component used to process image and media files, contains a heap-based buffer overflow vulnerability. A local attacker could exploit this flaw to execute arbitrary code with elevated privileges, potentially compromising system integrity and accessing sensitive user data.

Technical details

A heap-based buffer overflow exists in the Microsoft Windows Codecs Library, likely triggered during the processing of malformed image or codec data. The vulnerability requires local access to the system and does not require user interaction or authentication. Successful exploitation allows an attacker to execute arbitrary code in the context of the affected application or system process, potentially leading to privilege escalation. A patch is available from Microsoft via the Security Update Guide.

Affected products

  • Microsoft Windows Codecs Library

Timeline

  • 2026-09-08: disclosed

References

Related threats