Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.19044.0 (custom) before 10.0.19044.6809
affected
10.0.19045.0 (custom) before 10.0.19045.6809
affected
10.0.22631.0 (custom) before 10.0.22631.6491
affected
10.0.22631.0 (custom) before 10.0.22631.6491
affected
10.0.26100.0 (custom) before 10.0.26100.7623
affected
10.0.26200.0 (custom) before 10.0.26200.7623
affected
10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.17763.0 (custom) before 10.0.17763.8276
affected
10.0.20348.0 (custom) before 10.0.20348.4648
affected
10.0.25398.0 (custom) before 10.0.25398.2092
affected
10.0.26100.0 (custom) before 10.0.26100.32230
affected
10.0.26100.0 (custom) before 10.0.26100.32230
affected
Description
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Problem types
CWE-122: Heap-based Buffer Overflow
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20837 (Windows Media Remote Code Execution Vulnerability)