CVE-2026-58542: Windows Media Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Other sources
Windows Media Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650
Event History
Frequently Asked Questions
Which systems should be prioritized for assessment?
Assess Microsoft Windows 11 and Microsoft Windows Server 2025 systems, including Windows 11 24H2, 25H2, and 26H1, where Windows Media is present.
What access and interaction does exploitation require?
The vulnerability is rated for local attack access with no privileges required. Exploitation requires user interaction.