ZeroHour

CVE-2026-58600

mass

Heap Buffer Overflow in Microsoft Windows Codecs Library — Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-58600 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, the Windows component used to decode media and image formats. Per the CVSS vector, exploitation requires local access and user interaction (UI:R), meaning an attacker would most plausibly need a local user to open or preview crafted content processed by the codec library. A successful exploit allows an unprivileged attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability. The affected component ships as part of Windows, so broadly deployed Windows releases are in scope, although the source data does not specify exact affected versions or patch levels. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-58600 via Windows Update as soon as it is released, and check Microsoft's advisory for the exact affected version ranges since they are not listed in the source data. Until patched, caution users against opening untrusted image or media files, since exploitation requires local user interaction. Prioritize multi-user workstations, terminal/RDS servers, and kiosk-style systems, where a local privilege escalation has the greatest impact.

Affected
Microsoft Windows (Windows Codecs Library component)
Estimated exposure
mass≈1 billion+ Windows devices (component ships with Windows) — The Windows Codecs Library is a standard component of Windows, and Microsoft's Windows install base is publicly estimated at over 1 billion active devices, so effectively the entire Windows installed base is exposed pending version details…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.