CVE-2026-58599: HEVC Video Extensions Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Other sources
HEVC Video Extensions Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.5.25.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.86.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.87.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.85.0
Event History
Frequently Asked Questions
Which installations should be included in the affected-product review?
Review systems with Microsoft HEVC Video Extensions from Device Manufacturer, Microsoft HEVC Video Extensions, or Microsoft HEVC Video Extensions for Licensed Applications installed.
Does an attacker need an account or existing privileges to exploit this issue?
No privileges are required according to the CVSS vector. Exploitation is rated as local access, so network-only reachability is not indicated by the provided data.
Is user interaction required for exploitation?
Yes. The CVSS vector specifies user interaction is required, although the provided data does not identify the specific action a user must take.