CVE-2026-81353: HEIF Image Extensions Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Other sources
HEIF Image Extensions Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft HEIF Image Extension<1.2.48.0
1.2.48.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.48.0
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionSeverity
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates local access and user interaction are required. The attacker does not need existing privileges.
2
What is the potential impact of successful exploitation?
Successful exploitation can allow code execution with high impact to confidentiality, integrity, and availability.
3
Is this directly exposed as a network-based attack?
The supplied CVSS attack vector is local (AV:L). The available data does not identify a network service or remotely reachable interface as the attack path.