ThreatCluster

CVE-2025-23157 and CVE-2025-23158 Address Vulnerabilities in Media Processing

First seen 18 Feb 2026, 09:15 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

CVE-2025-23157 and CVE-2025-23158 were published on May 1, 2025, addressing vulnerabilities in the media processing component of the Venus driver. CVE-2025-23157 involves an out-of-bounds access issue, while CVE-2025-23158 addresses incorrect queue size handling. These vulnerabilities could potentially affect systems utilizing the Venus driver.

Timeline

2025-05-01
CVE-2025-23157 published
2025-05-01
CVE-2025-23158 published
2026-02-18
Article published detailing CVE-2025-23157
2026-02-18
Article published detailing CVE-2025-23158