Junglewise Threat Intelligence

CVE-2026-81352: Microsoft Windows Codecs Library heap buffer overflow

CVE-2026-81352 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Windows Codecs Library is a core Windows component responsible for processing audio and video files. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code remotely without authentication, potentially leading to complete system compromise and data theft.

Technical details

The vulnerability is a heap-based buffer overflow in the Windows Codecs Library, a system component that decodes multimedia formats. The vulnerability can be triggered over the network (remote code execution) without requiring authentication or user interaction. An attacker can exploit this flaw by sending specially crafted audio or video data to trigger the overflow, allowing arbitrary code execution with the privileges of the affected process. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Windows Codecs Library <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats