CVE-2026-62706
massOut-of-bounds read in Microsoft Windows Media Foundation enables network RCE
CVE-2026-62706 is an out-of-bounds read (CWE-125), also tagged with stack-based buffer overflow (CWE-121), in Microsoft Windows Media Foundation, the built-in Windows component that parses and renders audio and video content. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an unauthenticated remote attacker can trigger the flaw over a network, but exploitation likely requires a user to open a maliciously crafted media file or load attacker-supplied media content, such as through a webpage or shared file. A successful exploit allows the attacker to execute code in the context of the user who opens the content, with high impact on confidentiality, integrity, and availability of that system. Any Windows installation shipping Media Foundation is affected; the source data does not specify affected or fixed Windows version ranges. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.6% (45th percentile), so it is not believed to be exploited in the wild yet.
What to do: Check Microsoft's security advisory for this CVE to identify affected and fixed Windows builds, and apply the corresponding update as soon as it is available on Windows Update or via your patch management process. Until patched, treat untrusted media files and web-delivered media content with caution, since exploitation requires user interaction; prioritize patching shared workstations, kiosks, and endpoints whose users regularly open files or browse from untrusted sources. Monitor vendor channels for updated guidance, as no public PoC or in-the-wild exploitation is known at this time.
| Microsoft Windows Media Foundation | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-121, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.