Executive brief
A vulnerability in Windows Media components could allow an unauthorized person to access sensitive information over a network. Windows Media is a suite of multimedia tools used for playing and managing audio and video files on Windows operating systems. While this flaw does not allow an attacker to take control of a system, it could lead to the exposure of private data that should otherwise be protected.
Technical details
An information disclosure vulnerability (CWE-200) exists in Windows Media components across multiple versions of Windows and Windows Server. The vulnerability is exploitable over the network without requiring any special privileges or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows an unauthorized actor to disclose sensitive information, though it does not provide a mechanism for remote code execution or service disruption. Microsoft has released security updates to address this issue in affected versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Update Guide published