Junglewise Threat Intelligence

CVE-2026-58600: Microsoft Windows Codecs Library heap buffer overflow

CVE-2026-58600 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft's Windows Codecs Library is a system component that processes audio and video formats on Windows machines. A heap-based buffer overflow in this library allows a local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system. This vulnerability requires local access to exploit but poses a significant risk for privilege escalation attacks.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Windows Codecs Library, allowing local privilege escalation. The vulnerability is triggered through improper handling of codec data, enabling an attacker with local system access to overflow a heap buffer and execute arbitrary code in the context of a privileged process. The attack vector is local and requires user interaction or local code execution capability. Patch availability information is not specified in the advisory details provided.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats