Description
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Windows Media component of Microsoft Windows that permits an attacker to read sensitive data that should be protected. The vulnerability is classified as a classic information‑disclosure weakness (CWE‑200). The description states that an unauthorized actor can disclose information over a network, meaning the flaw does not require local privileges or special conditions beyond normal network access. The impact is the unauthorized exposure or leakage of data transmitted or processed by the Windows Media subsystem.

Affected Systems

As detailed by the CNA, the issue affects multiple Windows operating system releases: Windows 10 Build 1809, 21H2, and 22H2; Windows 11 Builds 24H2, 25H2, and 26H1; and Windows Server releases 2019, 2022, and 2025, including both full installations and Server Core editions. All of these releases contain components of the Windows Media framework that provide the exposed path.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity for this information‑disclosure flaw. The EPSS score of less than 1% indicates that current attacker activity against this vulnerability is expected to be very low. The flaw is not listed in the CISA KEV catalog, and no publicly documented exploits are known. Attackers would need network connectivity to a vulnerable system and would likely send crafted media packets or trigger Windows Media service traffic; the exact protocol or service is not specified, so the precise exploitation method is inferred from standard media usage patterns. Given the moderate score and low exploitation probability, this vulnerability is considered a moderate risk in environments where the Windows Media component is exposed to untrusted networks.

Generated by OpenCVE AI on July 31, 2026 at 07:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Windows cumulative update for CVE‑2026‑50415, using the update information provided in the Microsoft Security Response Center advisory.
  • If the Windows Media feature is not required, permanently disable Windows Media Player or remove the Windows Media subcomponents via the appropriate settings or registry tweaks.
  • Restrict inbound or outbound Windows Media traffic by configuring Windows Firewall rules or network security controls to limit exposure of media services to trusted sources only.

Generated by OpenCVE AI on July 31, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.
Title Windows Media Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-200
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:58.371Z

Reserved: 2026-06-04T18:56:53.259Z

Link: CVE-2026-50415

cve-icon Vulnrichment

Updated: 2026-07-15T14:20:24.505Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:45:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor