CVE-2010-2745 is a memory corruption vulnerability in Microsoft Windows Media Player versions 9 through 12, affecting various Windows operating systems. It arises from improper object deallocation during browser reloads, allowing user-assisted remote attackers to execute arbitrary code through specially crafted media content embedded in HTML. With a CVSS score of 9.3, this vulnerability is critical, requiring user interaction (medium attack complexity) but enabling complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry exists for a related exploit targeting Firefox, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_media_player:10:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_media_player:12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.