Known Vulnerabilities for Windows Media Player by Microsoft

Listed below are 10 of the newest known vulnerabilities associated with "Windows Media Player" by "Microsoft".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2017-11768 Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2... 2.5 - LOW 2017-11-15 2022-05-23
CVE-2015-1728 Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a ... 9.3 - HIGH 2015-06-10 2018-10-12
CVE-2014-2671 Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) ... 6.8 - MEDIUM 2014-03-31 2017-08-29
CVE-2013-3127 The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Wind... 9.3 - HIGH 2013-07-10 2018-10-12
CVE-2010-3138 Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain ... 9.3 - HIGH 2010-08-27 2018-10-12
CVE-2010-2745 Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which ... 9.3 - HIGH 2010-10-13 2023-12-07
CVE-2010-1042 Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a d... 4.3 - MEDIUM 2010-03-23 2017-08-17
CVE-2010-0718 Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (... 4.3 - MEDIUM 2010-02-26 2017-08-17
CVE-2010-0268 Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 20... 9.3 - HIGH 2010-04-14 2018-10-12
CVE-2009-0555 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compress... 9.3 - HIGH 2009-10-14 2019-02-28

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoftWindows Media PlayerxpAllAllAll
ApplicationMicrosoftWindows Media Player9.00.00.3349AllAllAll
ApplicationMicrosoftWindows Media Player9.00.00.3250AllAllAll
ApplicationMicrosoftWindows Media Player9.00.00.2980AllAllAll
ApplicationMicrosoftWindows Media Player9AllAllAll
ApplicationMicrosoftWindows Media Player8.00.00.4477AllAllAll
ApplicationMicrosoftWindows Media Player8AllAllAll
ApplicationMicrosoftWindows Media Player7.1AllAllAll
ApplicationMicrosoftWindows Media Player7AllAllAll
ApplicationMicrosoftWindows Media Player6.4AllAllAll
ApplicationMicrosoftWindows Media Player6.3AllAllAll
ApplicationMicrosoftWindows Media Player12AllAllAll
ApplicationMicrosoftWindows Media Player11.0.6000.6324AllAllAll
ApplicationMicrosoftWindows Media Player11.0.5721.5230AllAllAll
ApplicationMicrosoftWindows Media Player11.0.5721.5145AllAllAll
ApplicationMicrosoftWindows Media Player11AllAllAll
ApplicationMicrosoftWindows Media Player10.00.00.4036AllAllAll
ApplicationMicrosoftWindows Media Player10.00.00.4019AllAllAll
ApplicationMicrosoftWindows Media Player10.00.00.3990AllAllAll
ApplicationMicrosoftWindows Media Player10.00.00.3646AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report