CVE-2026-70351: Microsoft WebP Image Extension Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft WebP Image Extension Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.31.0
Event History
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The issue is remotely exploitable without authentication, but it requires user interaction. The provided data does not specify the exact interaction or delivery method.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which product is affected?
The affected software identified in the data is Microsoft WebP Image Extension. No affected versions, fixed versions, or configuration details are provided.