ZeroHour

CVE-2026-81353

mass

Heap-Based Buffer Overflow in Microsoft Windows Codecs Library Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-81353 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Codecs Library, the built-in Windows component that decodes image and media formats. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires local access and user interaction: a user must be induced to open or preview a crafted media/image file that the codec library parses, and no special privileges are needed. Successful exploitation lets an unauthorized attacker execute arbitrary code locally in the user's context, with high impact on confidentiality, integrity, and availability (CVSS 7.8). Any Windows installation containing the affected codec library is potentially affected, but because the attack is local and user-interaction dependent, remote/network exposure is not the primary risk. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.4% probability of exploitation within 30 days, so no exploitation is known.

What to do: Install the Microsoft security update addressing CVE-2026-81353 via Windows Update, and check Microsoft's advisory for the patched build numbers applicable to your Windows release. Until patched, instruct users not to open image or media files from untrusted sources, and prioritize patching systems where users routinely handle untrusted content, such as shared workstations, kiosks, and design or marketing machines.

Affected
Microsoft Windows Codecs Library (component of Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows installations (codec library ships as a standard component of Windows) — The Windows Codecs Library ships with essentially all modern Windows client installs, and Windows' active install base is on the order of a billion devices, so affected installations plausibly track that population, though the local,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.