CVE-2026-62744
massHeap Buffer Overflow in Microsoft Windows Media Foundation Enables Network RCE
CVE-2026-62744 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Media Foundation, the built-in Windows component that parses and renders audio and video content. A remote, unauthenticated attacker can trigger the flaw by getting a user to process maliciously crafted media content, consistent with the CVSS network-vector, user-interaction requirement. Successful exploitation could allow the attacker to execute arbitrary code in the context of the affected user. Any Windows system where the affected Media Foundation component processes untrusted media is in scope; Microsoft has not published specific version ranges in the provided data. Exploitation status is currently quiet: no public proof-of-concept, no CISA KEV listing, and an EPSS 30-day exploitation probability of 0.8%.
What to do: Apply Microsoft's security update for Windows Media Foundation as soon as it is released, via Windows Update or your patch management process, and check Microsoft's advisory for the exact affected Windows versions and KB references. Until patched, avoid opening audio/video files or untrusted media content from unknown sources, and prioritize systems that routinely handle third-party media (workstations, kiosks, media-processing servers). Verify remediation by confirming the component update is installed on all Windows endpoints.
| Microsoft Windows Media Foundation (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.