CVE-2026-81352
massHeap Buffer Overflow in Microsoft Windows Codecs Library Enables Remote Code Execution
CVE-2026-81352 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, the built-in component that parses image and media content on Windows. Per the CVSS vector (network vector with user interaction required, no privileges needed), an attacker would trigger the flaw by getting a user on a vulnerable system to process specially crafted media content, such as opening a malicious image or video delivered via email, web, or messaging. Successful exploitation allows an unauthorized attacker to execute code in the context of the affected user, with high impact on confidentiality, integrity, and availability. Any Windows installation shipping the affected Codecs Library component is potentially affected, although the specific affected Windows version ranges were not disclosed in the available data. Exploitation status is quiet so far: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at about 0.5% (41st percentile).
What to do: Install Microsoft's security update for CVE-2026-81352 through the standard Windows Update channel as soon as it is offered, and verify patch status in Windows Update history. Until patched, treat unsolicited or untrusted media files (images, video) from email, web, and messaging with caution, since user interaction is required to exploit this flaw. No public proof-of-concept or in-the-wild exploitation is known at this time.
| Microsoft Windows (Windows Codecs Library component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.