CVE-2026-70203
Windows Media Player Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a Windows Media Player flaw that can let an attacker run code over the network on unpatched Windows machines; most small businesses should act quickly to install the Microsoft fixes for Windows 10/11 and Windows Server that were affected.
CVE-2026-70203 is a heap-based buffer overflow in Windows Media Player that can be triggered to achieve remote code execution over a network connection without valid credentials.
What to do now
- Check whether your Windows systems are using Windows Media Player (or have Media Player components/features installed) and confirm their Windows version/build.
- Compare each affected machine’s Windows version against the fixed versions listed by Microsoft for CVE-2026-70203.
- Install the latest available Windows updates that include the fix for CVE-2026-70203, prioritizing Windows Media Player–capable machines first.
- Reboot after updates and verify the machine reports the updated build numbers (the fixed versions below) in Windows Update/System Information.
- If you can’t patch immediately, restrict network access to the affected endpoints (limit inbound from untrusted networks) until updates are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-70203 and every CVE in our database. Create a free account — no credit card required.
Create Free Account