Microsoft Hevc Video Extensions — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Hevc Video Extensions, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2026-58599 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
CVE-2026-58600 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.