Impact
A heap-based buffer overflow in Windows Media Player can be triggered remotely, allowing an attacker to execute arbitrary code by sending malicious media files over a network. This flaw, categorized as CWE-122, lets an unauthorized party gain code execution privileges that match the privileges of the media player process, potentially compromising confidentiality, integrity, and availability. The likely attack vector is network delivery of crafted media content.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012 through 2025, including their Server Core installations. All listed builds are vulnerable until patched.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is not available, so the current exploitation probability cannot be determined. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to deliver a crafted media file to the target, typically via an open network port managed by Windows Media Player. Given the high severity and lack of a widely known public exploit, the risk remains significant for organizations that run unpatched Windows installations.
OpenCVE Enrichment