CVE-2026-72960
massHeap Buffer Overflow RCE in Microsoft Windows Media Player
CVE-2026-72960 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Media Player that Microsoft has rated High (CVSS 8.8). The CVSS vector indicates the flaw is reachable over a network without authentication, but requires user interaction — in practice an attacker must get a user to open or play a maliciously crafted media file. Successful exploitation yields code execution in the context of the local user, with high confidentiality, integrity, and availability impact. All Windows users with the affected Windows Media Player component are exposed; specific affected version ranges have not been detailed in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a modest 0.8% probability of exploitation within 30 days (53rd percentile).
What to do: Apply the Microsoft Windows security update addressing CVE-2026-72960 as soon as it is published, and verify rollout through your patch management/Windows Update compliance reporting — check Microsoft's advisory for the exact affected and fixed builds. Until patched, caution users against opening media files from untrusted or unknown sources, since exploitation requires user interaction. Because there is no known exploitation or public PoC, there is time to patch through normal patch cycles, but do not defer past the next update window.
| Microsoft Windows Media Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.