CVE-2009-1331 describes an integer overflow vulnerability in Microsoft Windows Media Player (WMP) version 11.0.5721.5260. This flaw allows a remote attacker to trigger a denial of service (application crash) by enticing a user to open a specially crafted .mid file. The vulnerability has a critical CVSS score of 9.3, indicating a high potential for impact, with an attack vector over the network and medium attack complexity. While there is no evidence of active exploitation, a proof-of-concept exploit is publicly available on ExploitDB, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.5721.5260CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_media_player:11.0.5721.5260:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.