ZeroHour

CVE-2026-72960

mass

Heap Buffer Overflow RCE in Microsoft Windows Media Player

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-72960 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Media Player that Microsoft has rated High (CVSS 8.8). The CVSS vector indicates the flaw is reachable over a network without authentication, but requires user interaction — in practice an attacker must get a user to open or play a maliciously crafted media file. Successful exploitation yields code execution in the context of the local user, with high confidentiality, integrity, and availability impact. All Windows users with the affected Windows Media Player component are exposed; specific affected version ranges have not been detailed in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a modest 0.8% probability of exploitation within 30 days (53rd percentile).

What to do: Apply the Microsoft Windows security update addressing CVE-2026-72960 as soon as it is published, and verify rollout through your patch management/Windows Update compliance reporting — check Microsoft's advisory for the exact affected and fixed builds. Until patched, caution users against opening media files from untrusted or unknown sources, since exploitation requires user interaction. Because there is no known exploitation or public PoC, there is time to patch through normal patch cycles, but do not defer past the next update window.

Affected
Microsoft Windows Media Player
Estimated exposure
massorder of hundreds of millions of Windows installations (Windows Media Player ships with the Windows client OS; the Windows desktop installed base is over a… — The affected component is bundled with Windows, so exposure roughly tracks the Windows client install base (publicly estimated at >1 billion devices), reduced to an unknown degree by users on versions or configurations lacking the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.