AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2525

HIGH · CVSS 9.3 EPSS 23.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-10-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-2525
Severity
HIGH
CVSS
9.3
EPSS
23.32%
Microsoft Windows

Original NVD Description

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2) crafted streaming content, aka "Windows Media Runtime Heap Corruption Vulnerability."