Impact
A heap-based buffer overflow in Windows Media Player allows an attacker to execute arbitrary code on the target system. The flaw is a classic out-of-bounds write that falls under the Common Weakness Enumeration CWE-122. When triggered, it enables the attacker to gain code execution privileges, potentially compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Microsoft Windows operating systems across multiple release lines, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 release trains 23H2, 24H2, 25H2, 26H1; and Windows Server versions 2016, 2019, 2022, and 2025 (both standard and Server Core installations).
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating a high severity level. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is network-based, inferred from the description that an unauthorized attacker can exploit the flaw over a network. Exploitation would require the attacker to engage the vulnerable Media Player component, likely by serving a specially crafted media file or otherwise interacting with the system’s media playback functionality.
OpenCVE Enrichment