ZeroHour

CVE-2026-70203

mass

Heap Buffer Overflow in Windows Media Player Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-70203 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Media Player that can be triggered over a network by content processed by the player. Per the CVSS vector, exploitation requires user interaction (UI:R) but no privileges, consistent with an attacker persuading a user to open or load attacker-crafted media content. A successful exploit yields code execution in the context of the affected application, with high impact to confidentiality, integrity, and availability. Any user running an affected version of Windows Media Player is exposed; the affected version ranges are not enumerated in the available data, so defenders should rely on Microsoft's advisory. Exploitation status is quiet: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns a modest 0.8% probability of exploitation within 30 days (55th percentile).

What to do: Apply Microsoft's security update for CVE-2026-70203 as soon as it is released, via Windows Update or your patch management tooling, since Windows Media Player fixes typically ship in the Windows cumulative updates. Until systems are patched, advise users not to open media files or streams from untrusted sources, as exploitation requires user interaction. Verify remediation by confirming hosts are current on Windows cumulative updates and by checking Microsoft's advisory for the exact affected product/version scope.

Affected
Microsoft Windows Media Player
Estimated exposure
massplausibly hundreds of millions of Windows endpoints (order of 10^8), since Windows Media Player ships by default with Windows desktops — Windows Media Player is bundled with Windows desktop editions and Microsoft has publicly reported on the order of a billion active Windows devices, so the population of potentially affected installations is best estimated at hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.