Heap Buffer Overflow in Microsoft Windows Codecs Library Enables Local Code Execution
AI analysis
CVE-2026-58599 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, patched by Microsoft as part of the September 2026 Patch Tuesday. The CVSS vector (AV:L, UI:R, no privileges required) indicates the flaw is triggered locally when the codecs library processes specially crafted content, requiring user interaction such as opening a malicious media or image file. A successful attacker can execute arbitrary code in the context of the local user with no prior privileges, with high impact on confidentiality, integrity, and availability. Any Windows system containing the affected Windows Codecs Library is exposed, though the source data does not enumerate specific Windows versions or builds. Exploitation is currently quiet: there is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's September 2026 security updates (Windows cumulative updates) to all supported systems, prioritizing user workstations where untrusted image or media files are routinely opened. Until systems are patched, treat unsolicited image and media files with caution, since exploitation requires user interaction to trigger the overflow. Verify through Windows Update or your patch-management tooling that the September 2026 cumulative update has been installed on each endpoint.
Affected
| Microsoft Windows (Windows Codecs Library component) | — |
Estimated exposure
masshundreds of millions of Windows devices (the codecs library ships as a default OS component) — The Windows Codecs Library is a built-in Windows component, so the plausible affected population is effectively the entire supported Windows install base, which public desktop OS market-share data puts in the hundreds of millions of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.