ZeroHour

CVE-2026-69649

mass

Heap-Based Buffer Overflow RCE in Microsoft Windows Raw Image Extension

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69649 is a heap-based buffer overflow (CWE-122) in the Windows Raw Image Extension, the Microsoft Store component that decodes camera raw image formats so Windows can display previews of files like NEF, CR2, and ARW. Per the CVSS vector, an unauthorized (unprivileged) remote attacker must convince a user to open or preview a crafted raw image file delivered over the network, for example via email, download, or chat, which triggers the heap overflow during parsing. Successful exploitation yields code execution with high impact on confidentiality, integrity, and availability, running in the context of the process that decodes the image. Any Windows system with the Raw Image Extension installed is affected; specific affected version numbers are not provided in the source data. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.8% probability of exploitation within 30 days.

What to do: Update the Raw Image Extension to the latest version through the Microsoft Store (check for app updates) or via Microsoft's security update channels, following the version guidance in Microsoft's advisory. As interim mitigation, avoid opening or previewing untrusted raw image files with Explorer or other apps that use this codec, and consider removing the extension on systems that do not need raw camera file support. Prioritize internet-facing or mail-heavy workstations where users routinely handle files from external sources.

Affected
Microsoft Windows Raw Image Extension (Microsoft Store codec app)
Estimated exposure
massplausibly hundreds of millions of Windows endpoints (the extension ships widely via Microsoft Store preinstall/auto-install on Windows 10/11) — The Raw Image Extension is broadly preinstalled or auto-installed on Windows 10/11 consumer and business desktops to enable raw camera file previews, and the Windows install base exceeds one billion devices, so a seven-figure-plus endpoint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.