CVE-2026-70351

8.8

Microsoft · WebP Image Extension

An integer overflow in the Microsoft WebP Image Extension allows an unauthenticated attacker to achieve remote code execution via a specially crafted image file.

Executive summary

A critical integer overflow vulnerability in the Microsoft WebP Image Extension could allow an unauthenticated attacker to execute arbitrary code on the host system.

Vulnerability

This vulnerability is caused by an integer overflow or wraparound condition in the image processing logic, which can subsequently trigger a heap-based buffer overflow. An unauthenticated attacker can exploit this remotely by enticing a user to open a malicious WebP file.

Business impact

The potential for remote code execution presents a severe risk to organizational security, as it allows attackers to gain full control over affected endpoints. With a CVSS score of 8.8, this vulnerability is classified as High, reflecting the significant threat of data exfiltration, malware installation, and lateral movement within the network.

Remediation

Immediate Action: Update the Microsoft WebP Image Extension to version 1.2.31.0 or later via the Microsoft Store or standard Windows update channels.

Proactive Monitoring: Monitor system logs for unusual process execution patterns associated with image rendering applications or suspicious network traffic originating from workstations.

Compensating Controls: Deploy endpoint protection software capable of detecting buffer overflow attempts and restrict the execution of unauthorized image-processing software in sensitive environments.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution, this vulnerability poses a substantial risk to all Windows systems utilizing the WebP Image Extension. Administrators should prioritize the deployment of the vendor-supplied patch to version 1.2.31.0 to eliminate the underlying integer overflow flaw and prevent potential exploitation.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources