ZeroHour

CVE-2026-62744

mass

Heap Buffer Overflow in Microsoft Windows Media Foundation Enables Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-62744 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Media Foundation, the built-in Windows component that parses and renders audio and video content. A remote, unauthenticated attacker can trigger the flaw by getting a user to process maliciously crafted media content, consistent with the CVSS network-vector, user-interaction requirement. Successful exploitation could allow the attacker to execute arbitrary code in the context of the affected user. Any Windows system where the affected Media Foundation component processes untrusted media is in scope; Microsoft has not published specific version ranges in the provided data. Exploitation status is currently quiet: no public proof-of-concept, no CISA KEV listing, and an EPSS 30-day exploitation probability of 0.8%.

What to do: Apply Microsoft's security update for Windows Media Foundation as soon as it is released, via Windows Update or your patch management process, and check Microsoft's advisory for the exact affected Windows versions and KB references. Until patched, avoid opening audio/video files or untrusted media content from unknown sources, and prioritize systems that routinely handle third-party media (workstations, kiosks, media-processing servers). Verify remediation by confirming the component update is installed on all Windows endpoints.

Affected
Microsoft Windows Media Foundation (Windows component)
Estimated exposure
masswell over 1 billion Windows installations ship Media Foundation as a core OS component — Media Foundation is bundled with Microsoft Windows, which runs on more than a billion active devices worldwide per Microsoft's long-standing public figures, so the potential installed base is effectively the global Windows estate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.