cve-2026-81352
HIGH CVSS 8.8 fkie_nvd
Description
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
- Attack Vector
- NETWORK
- Attack Complexity
- LOW
- Privileges Required
- NONE
Affected Products
- microsoft web_media_extensions
- microsoft windows_10_21h2
- microsoft windows_10_22h2
- microsoft windows_11_23h2
- microsoft windows_11_24h2
- microsoft windows_11_25h2
- microsoft windows_11_26h1
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
2.8 | 5.9 | secure@microsoft.com |
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
3.9 | 5.9 | nvd@nist.gov |
CPE configurations
OR
| CPE | Version range | Vulnerable |
|---|---|---|
cpe:2.3:a:microsoft:web_media_extensions:*:*:*:*:*:*:*:* |
< 1.2.42.0 | yes |
OR
| CPE | Version range | Vulnerable |
|---|---|---|
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
< 10.0.19044.7725 | no |
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* |
< 10.0.19044.7725 | no |
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
< 10.0.19044.7725 | no |
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:* |
< 10.0.19045.7725 | no |
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* |
< 10.0.19045.7725 | no |
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:* |
< 10.0.19045.7725 | no |
OR
| CPE | Version range | Vulnerable |
|---|---|---|
cpe:2.3:a:microsoft:web_media_extensions:*:*:*:*:*:*:*:* |
< 2.1.51.0 | yes |
OR
| CPE | Version range | Vulnerable |
|---|---|---|
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* |
— | no |
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:* |
— | no |
NVD metadata
- NVD status
- Analyzed
- Source identifier
secure@microsoft.com
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81352 Vendor Advisory, Patch
Linked Vulnerabilities
No linked vulnerabilities found.
{
"affected": [
{
"affectedData": [
{
"platforms": [
"Windows 10 Version 21H2 for 32-bit Systems",
"Windows 10 Version 21H2 for ARM64-based Systems",
"Windows 10 Version 21H2 for x64-based Systems",
"Windows 10 Version 22H2 for 32-bit Systems",
"Windows 10 Version 22H2 for ARM64-based Systems",
"Windows 10 Version 22H2 for x64-based Systems",
"Windows 11 Version 23H2 for ARM64-based Systems",
"Windows 11 Version 23H2 for x64-based Systems",
"Windows 11 Version 24H2 for ARM64-based Systems",
"Windows 11 Version 24H2 for x64-based Systems",
"Windows 11 Version 25H2 for ARM64-based Systems",
"Windows 11 Version 25H2 for x64-based Systems",
"Windows 11 Version 26H1 for ARM64-based Systems",
"Windows 11 version 26H1 for x64-based Systems"
],
"product": "Web Media Extensions",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "1.2.42.0",
"status": "affected",
"version": "1.0.0.0",
"versionType": "custom"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:web_media_extensions:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D1EFCE08-8EF2-43F4-825A-684E59E84925",
"versionEndExcluding": "1.2.42.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "26BFC889-B503-48BF-9D82-5B3043D9A6B3",
"versionEndExcluding": "10.0.19044.7725",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E6F2C029-D78A-4FAA-B2E8-FD79C2CABC32",
"versionEndExcluding": "10.0.19044.7725",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "0B423BD2-DDDC-4869-9B98-3275F53B92F1",
"versionEndExcluding": "10.0.19044.7725",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "254EF7C4-707D-4480-BC27-56F64175A9AD",
"versionEndExcluding": "10.0.19045.7725",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "B318C958-84F6-4E33-A95C-6E95C7E286EB",
"versionEndExcluding": "10.0.19045.7725",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "9828DC67-F252-4E2B-AFE9-C404BAF414E0",
"versionEndExcluding": "10.0.19045.7725",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:web_media_extensions:*:*:*:*:*:*:*:*",
"matchCriteriaId": "746C6FE6-3DAA-4655-9E11-163C257D01E0",
"versionEndExcluding": "2.1.51.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "3DBD1FAA-62DB-4D32-9262-5705CFAE6442",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "C9CA92CD-6DE8-4945-8759-1CD7D35E8B0C",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "B576A7A8-8F49-412C-8726-90431E404BD3",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1799DC19-34BA-42B4-A6DC-02774202DE22",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "1865378F-C9F4-455E-9D81-30DF531136D8",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "AAAB3FDE-4FF2-47DE-9BDA-25B2855054E7",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "6A2310E5-5BEE-40B4-994B-386E22C986A4",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "DA9F6F61-46D3-4ECD-8B5D-1484222B7364",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network."
}
],
"id": "CVE-2026-81352",
"lastModified": "2026-09-23T15:39:40.480",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "secure@microsoft.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-81352",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T04:26:56.381369Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-08T18:20:52.940",
"references": [
{
"source": "secure@microsoft.com",
"tags": [
"Vendor Advisory",
"Patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81352"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-122"
}
],
"source": "secure@microsoft.com",
"type": "Secondary"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)