ZeroHour

CVE-2026-69715

mass

Out-of-Bounds Read Code Execution Flaw in Microsoft Windows DirectShow

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69715 is a memory-safety vulnerability in Windows DirectShow, Microsoft's multimedia framework, classified as an out-of-bounds read (CWE-125) with a heap-based buffer overflow also listed (CWE-122). According to Microsoft's scoring, an unauthorized attacker can trigger the flaw remotely over a network (AV:N, AC:L, PR:N, UI:N), i.e., through network-supplied input processed by DirectShow without authentication or user interaction. Successful exploitation allows the attacker to execute arbitrary code on the affected system. Any Windows system running the DirectShow component is potentially affected, which broadly includes Windows desktop and server deployments. There is currently no public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 1.0% chance of exploitation in the next 30 days, so no in-the-wild exploitation is known at this time.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, checking the MSRC advisory for the list of affected Windows builds and prioritizing hosts that ingest or process media content over the network (media servers, transcoding or streaming services, and applications parsing remote/untrusted media). Because no public PoC or known exploitation exists, emergency patching is not urgent, but defenders should verify DirectShow-exposed services are covered when the fix ships; no workaround is specified in the available data.

Affected
Microsoft Windows DirectShow
Estimated exposure
masson the order of 1,000,000,000+ Windows installations (DirectShow ships as a standard Windows component) — DirectShow is a core multimedia component included with Microsoft Windows, which Microsoft has publicly stated runs on more than one billion active devices, so exposure is estimated at the scale of the entire Windows installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.