ZeroHour

CVE-2026-81352

mass

Heap Buffer Overflow in Microsoft Windows Codecs Library Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-81352 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, the built-in component that parses image and media content on Windows. Per the CVSS vector (network vector with user interaction required, no privileges needed), an attacker would trigger the flaw by getting a user on a vulnerable system to process specially crafted media content, such as opening a malicious image or video delivered via email, web, or messaging. Successful exploitation allows an unauthorized attacker to execute code in the context of the affected user, with high impact on confidentiality, integrity, and availability. Any Windows installation shipping the affected Codecs Library component is potentially affected, although the specific affected Windows version ranges were not disclosed in the available data. Exploitation status is quiet so far: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at about 0.5% (41st percentile).

What to do: Install Microsoft's security update for CVE-2026-81352 through the standard Windows Update channel as soon as it is offered, and verify patch status in Windows Update history. Until patched, treat unsolicited or untrusted media files (images, video) from email, web, and messaging with caution, since user interaction is required to exploit this flaw. No public proof-of-concept or in-the-wild exploitation is known at this time.

Affected
Microsoft Windows (Windows Codecs Library component)
Estimated exposure
mass≈1 billion+ Windows installations (Codecs Library is a built-in Windows component) — The Windows Codecs Library ships with Windows 10/11, whose combined installed base is on the order of a billion devices, so exposure is assumed to approach the full supported Windows fleet pending Microsoft's per-version affected list.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.