Executive brief
Windows Direct Show is a multimedia framework used to play and stream audio and video content on Windows systems. An out-of-bounds read vulnerability in this component could allow a remote attacker to execute arbitrary code on affected systems by sending specially crafted media files or streams over the network, potentially compromising system integrity and enabling unauthorized access.
Technical details
The vulnerability is an out-of-bounds read in Windows Direct Show, a multimedia framework component. The flaw allows remote code execution over the network without requiring authentication or user privileges. An attacker can exploit this by delivering malicious media content that triggers the out-of-bounds memory access, leading to arbitrary code execution in the context of the affected process. The attack vector is network-based and does not require user interaction beyond accepting or processing media content.
Affected products
- Microsoft Windows Direct Show <UNKNOWN>
Timeline
- 2026-09-08: disclosed