Description
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Windows Media component exposes sensitive internal data to an unauthorized actor, permitting local disclosure of information that should remain confidential. The vulnerability is classified as a CWE-200 information disclosure weakness, indicating that improper handling of private data is occurring. The exploit does not grant remote code execution or elevate privileges; it simply lets an attacker with local access read sensitive data, which could include configuration files, user information, or other protected contents.

Affected Systems

Affected systems are Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 releases from 24H2 through 26H1, and Windows Server editions from 2012 R2 to 2025, in both full and core installations. All impacted operating systems run the default Windows Media runtime components that parse media files, which contain the vulnerable logic.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, reflecting local information disclosure. The EPSS score of < 1% shows a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an adversary must already have legitimate local access or coerce a user into opening a malicious media file to trigger the disclosure. No special privileges or remote connectivity are required, but the data accessed may support subsequent attacks.

Generated by OpenCVE AI on July 31, 2026 at 07:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for Windows Media that addresses the vulnerability.
  • Ensure that Windows 10, Windows 11, and Windows Server systems are updated to the latest cumulative update, which includes the fix.
  • If immediate patching is not possible, reduce the attack surface by disabling the Windows Media feature or enforcing AppLocker rules that block execution of media files.

Generated by OpenCVE AI on July 31, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Title Windows Media Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-200
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:09.221Z

Reserved: 2026-06-04T18:55:14.745Z

Link: CVE-2026-50394

cve-icon Vulnrichment

Updated: 2026-07-15T13:05:16.631Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:45:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor