VDB
CVE-2026-57087
CVE-2026-57087
PUBLISHED
CVSS 8.8 HIGH
Reported by microsoft · Published July 14, 2026
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0 |
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 |
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 |
| Microsoft | Windows 11 version 26H1 | 10.0.28000.0 |
| Microsoft | Windows Server 2016 | 10.0.14393.0 |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 |
| Microsoft | Windows Server 2019 | 10.0.17763.0 |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 |
| Microsoft | Windows Server 2022 | 10.0.20348.0 |
| Microsoft | Windows Server 2025 | 10.0.26100.0 |
| Microsoft | Windows Server 2025 (Server Core installation) | 10.0.26100.0 |
| microsoft | windows_server_2016 | 10.0.14393.0, 10.0.14393.0, 10.0.14393.0 |
| microsoft | windows_10_21H2 | 10.0.19044.0, 10.0.19044.0, 10.0.19044.0 |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0, 10.0.19045.0, 10.0.19045.0 |
| Microsoft | Windows Server 2016 | 10.0.14393.0, 10.0.14393.0, 10.0.14393.0 |
| microsoft | windows_11_25H2 | 10.0.26200.0, 10.0.26200.0, 10.0.26200.0 |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0, 10.0.14393.0, 10.0.14393.0 |
…and 19 more
Timeline
- Jul 14, 2026 CVE Published
- Jul 15, 2026 Coalition ESS Score
- Jul 16, 2026 Security Advisory
- Jul 22, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 20, 2026 Security Advisory
References
- Microsoft Windows Media Foundation Remote Code Execution Vulnerability vendor-advisorypatch