Executive brief
A security vulnerability exists in Windows Media, a component of the Windows operating system used for playing and managing multimedia content. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that they are not authorized to see. This could lead to the exposure of private data or system details, though it does not allow the attacker to take control of the machine or delete files directly.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Windows Media component across multiple versions of Windows and Windows Server. The flaw allows a locally authenticated attacker with low privileges to gain access to sensitive information that should be restricted. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system, but no user interaction is required. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD