Executive brief
A security vulnerability has been identified in Windows Media Foundation, a core component of the Windows operating system used for processing multimedia files. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the computer. This could lead to the theft of personal data, installation of malicious software, or disruption of business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Windows Media Foundation. The flaw is triggered when the component improperly handles specially crafted multimedia content. An attacker can exploit this by convincing a local user to open a malicious file or visit a compromised website that hosts such content. Successful exploitation allows for arbitrary code execution with the privileges of the logged-in user. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory