Sceawere

Vulnerability Detail

CVE-2026-105250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft IMA Decoder Divide-by-Zero

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
n/a
Product
vgmstream
Attack Type
Divide By Zero
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T08:17:15.610Z",
  "pubdate": "2026-10-05T08:17:15.610Z",
  "executiveSummary": "A divide-by-zero vulnerability exists in vgmstream up to r2117 within the Microsoft IMA Decoder component. The flaw is located in the decode_ms_ima function within src/coding/ima_decoder.c. This vulnerability allows a remote attacker to trigger a crash, potentially leading to a denial-of-service condition.\nThe vulnerability occurs due to improper input validation when processing malformed audio data, specifically when the codec encounters parameters that result in a division operation by an uninitialized or zero-valued divisor. Successful exploitation requires the application to process a specially crafted malicious audio file. There are no authentication requirements for an attacker to target the decoder, and the vulnerability can be exploited remotely by delivering the malicious payload to a system utilizing the affected vgmstream version.\nThe primary risk implication is system instability and service disruption, as the resulting exception typically forces the termination of the host process. Users of vgmstream are advised to restrict processing of untrusted audio files and ensure that the library is isolated within a sandboxed environment where possible.",
  "technicalDetails": "The vulnerability resides in the src/coding/ima_decoder.c file of the vgmstream library, specifically within the decode_ms_ima function responsible for processing Microsoft IMA ADPCM audio streams. The root cause is an insufficient validation of codec-specific parameters extracted from the audio container format before performing arithmetic operations.\nIn the context of the IMA ADPCM decoding algorithm, the decoder relies on specific header fields to determine internal state variables, such as step size or predictor values. If an attacker provides a malformed file containing header fields that manipulate these internal variables to zero, the subsequent decoding loop attempts a division operation using these tainted values. Since the code does not perform an explicit check to verify that the divisor is non-zero before the instruction is executed, the CPU generates a floating-point or integer division exception (SIGFPE on POSIX systems), causing the application to crash.\nThe attack flow proceeds as follows: An attacker creates a malicious audio file where the metadata or IMA ADPCM stream headers are crafted to set the divisor variable to zero during the state initialization phase of the decode_ms_ima function. When the target application invokes vgmstream to parse or play this file, the library parses the malicious headers and stores the zero value in the corresponding internal state structure. As the decoding loop progresses to the point of processing audio blocks, the function triggers a division operation. The lack of an input sanitization routine allows this zero value to reach the divisor register, resulting in a hardware-level divide-by-zero exception.\nBecause the function processes data directly from the input stream, the exploitation is deterministic. If the library is integrated into a network service or a media player that automatically processes remote files, an attacker can trigger the crash remotely without requiring prior authentication or user interaction beyond the file delivery. The post-exploitation impact is limited to a denial-of-service (DoS) as the exception typically leads to an unhandled signal, resulting in the immediate termination of the vgmstream-based process. There is no evidence currently indicating that this primitive can be escalated to arbitrary code execution, though it effectively renders the affected component unusable when processing the malicious input."
}
CVE-2026-105250: Microsoft IMA Decoder Divide-by-Zero (MEDIUM Severity, CVSS: 4.3) | Sceawere