• PATCH AVAILABLE

CVE-2026-81352: pre-auth remote code execution in Microsoft Web Media Extensions

An unauthenticated attacker can trigger a heap-based buffer overflow in Microsoft Web Media Extensions to execute arbitrary code or crash the host. CVE-2026-81352 affects Web Media Extensions versions 1.0.0.0 through 1.2.41.0; the issue is fixed in 1.2.42.0. The vulnerability is exploitable over a network and does not require user interaction or valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.0048
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply the available fix immediately because this is a network-accessible, pre-auth remote code execution vulnerability with a critical 9.8 CVSS score.

What is CVE-2026-81352?

An unauthenticated attacker can trigger a heap-based buffer overflow in Microsoft Web Media Extensions to execute arbitrary code or crash the host. CVE-2026-81352 affects Web Media Extensions versions 1.0.0.0 through 1.2.41.0; the issue is fixed in 1.2.42.0. The vulnerability is exploitable over a network and does not require user interaction or valid credentials. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Web Media Extensions are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0.0 – before 1.2.42.01.2.42.0

Is CVE-2026-81352 being exploited?

No — there are no public reports of exploitation or public exploit code as of 2026-09-30.

How to fix CVE-2026-81352

  1. Update Web Media Extensions to 1.2.42.0 (the vendor-provided fix).
  2. If you cannot update immediately, restrict network exposure of systems using Web Media Extensions and block access from untrusted networks.
  3. Follow the vendor's guidance and apply any recommended configuration changes or mitigations.
  4. Monitor logs and endpoint telemetry for crashes, unexpected child processes, or signs of code execution tied to media handling.

Frequently asked questions

Is CVE-2026-81352 being actively exploited?

No — there are no public reports of active exploitation or public exploit code for Web Media Extensions as of 2026-09-30.

Which Web Media Extensions versions are affected by CVE-2026-81352?

Web Media Extensions versions 1.0.0.0 through 1.2.41.0 are affected; the issue is fixed in 1.2.42.0.

Is there a patch for CVE-2026-81352?

Yes, the vulnerability is fixed in Web Media Extensions version 1.2.42.0.

Does CVE-2026-81352 require authentication?

No, CVE-2026-81352 is exploitable without authentication and can be triggered over the network.

References