Junglewise Threat Intelligence

CVE-2026-81353: Microsoft Windows Codecs Library heap-based buffer overflow

CVE-2026-81353 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Microsoft Windows Codecs Library contains a heap-based buffer overflow vulnerability that allows a local attacker to execute arbitrary code on affected systems. Exploitation requires local system access but does not require user interaction, potentially allowing an attacker to escalate privileges or compromise system integrity after gaining initial access to a machine.

Technical details

The vulnerability is a heap-based buffer overflow in the Windows Codecs Library, a core Windows component responsible for encoding and decoding images and multimedia formats. An attacker with local access to the system can trigger the overflow by providing specially crafted input to the affected codec, leading to arbitrary code execution in the context of the application using the library. The attack does not require elevated privileges or network access, only the ability to run code or influence input on the local system. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Codecs Library

Timeline

  • 2026-09-08: disclosed

References

Related threats