ZeroHour

CVE-2026-62706

mass

Out-of-bounds read in Microsoft Windows Media Foundation enables network RCE

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-62706 is an out-of-bounds read (CWE-125), also tagged with stack-based buffer overflow (CWE-121), in Microsoft Windows Media Foundation, the built-in Windows component that parses and renders audio and video content. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an unauthenticated remote attacker can trigger the flaw over a network, but exploitation likely requires a user to open a maliciously crafted media file or load attacker-supplied media content, such as through a webpage or shared file. A successful exploit allows the attacker to execute code in the context of the user who opens the content, with high impact on confidentiality, integrity, and availability of that system. Any Windows installation shipping Media Foundation is affected; the source data does not specify affected or fixed Windows version ranges. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.6% (45th percentile), so it is not believed to be exploited in the wild yet.

What to do: Check Microsoft's security advisory for this CVE to identify affected and fixed Windows builds, and apply the corresponding update as soon as it is available on Windows Update or via your patch management process. Until patched, treat untrusted media files and web-delivered media content with caution, since exploitation requires user interaction; prioritize patching shared workstations, kiosks, and endpoints whose users regularly open files or browse from untrusted sources. Monitor vendor channels for updated guidance, as no public PoC or in-the-wild exploitation is known at this time.

Affected
Microsoft Windows Media Foundation
Estimated exposure
mass≈1 billion+ Windows devices (Media Foundation is a built-in component present on essentially all Windows client and server installs) — Media Foundation ships by default with supported Windows releases, and Windows runs on well over a billion devices worldwide per long-standing Microsoft and analyst estimates, so the component's install base is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Weakness
CWE-121, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.