CVE-2026-20464: Integer Overflow
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HEVC decoder (integer overflow leading to possible out of bounds write)to a version that resolves this vulnerability.Patch ALPS11104718 - Compensating control
Because exploitation may lead to remote escalation of privilege without user interaction once System privilege is obtained, restrict network access to components/services that expose HEVC decoding functionality (e.g., limit inbound access via firewall/ACL to only trusted sources).