Junglewise Threat Intelligence

CVE-2026-72960: Microsoft Windows Media Player heap buffer overflow

CVE-2026-72960 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Media Player is a media playback application built into Microsoft Windows. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a system by sending a specially crafted media file or stream over the network, potentially leading to complete system compromise without requiring user authentication or complex user interaction.

Technical details

This vulnerability is a heap-based buffer overflow in Windows Media Player's media processing code. The flaw allows an attacker to craft a malicious media file or network stream that triggers an out-of-bounds write to heap memory, overwriting adjacent heap structures. The attack is network-accessible and does not require authentication or special privileges. Successful exploitation enables arbitrary code execution in the context of the Media Player process, potentially allowing lateral movement or privilege escalation depending on the user's security context.

Affected products

  • Microsoft Windows Media Player

Timeline

  • 2026-09-08: disclosed

References

Related threats