ZeroHour

CVE-2026-69408

mass

Integer Overflow RCE in Microsoft Windows Media Foundation

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69408 is an integer overflow or wraparound flaw (CWE-190, also mapped to heap-based buffer overflow CWE-122) in Microsoft Windows Media Foundation, the Windows subsystem that parses and renders media content. According to the CVSS vector, the flaw is reachable over a network with low attack complexity, no privileges and no user interaction, indicating an attacker can trigger it directly via network-supplied media data without authentication. Successful exploitation allows an unauthorized attacker to execute arbitrary code on the target system with high impact on confidentiality, integrity and availability. Any Windows deployment running the affected Media Foundation component is exposed; the provided data does not specify which Windows versions are affected, so administrators must consult Microsoft's advisory for the exact version ranges. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 1.0% probability of exploitation within 30 days (61st percentile).

What to do: Monitor Microsoft's advisory (CNA [email protected]) for the exact affected Windows versions and apply the security update to those releases as soon as it is available, prioritizing internet-facing or media-processing systems given the 9.8 CVSS network vector. In the interim, restrict untrusted network media sources reaching Windows hosts where feasible and verify which Windows versions in your estate include the affected Media Foundation component. Reassess priority if a public PoC, KEV listing, or elevated EPSS score appears.

Affected
Microsoft Windows Media Foundation (component of Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows installations (Media Foundation is a core Windows component shipped on essentially all Windows client and server systems) — Media Foundation ships with the Windows operating system itself, and Windows runs on well over a billion active devices worldwide, so exposure is bounded only by the affected version ranges Microsoft lists in its advisory.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.