CVE-2010-0818

Windows MPEG-4 Codec - Remote Code Execution via Crafted Media Content

Title source: llm
STIX 2.1

Description

The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7318

Scores

EPSS 0.1394
EPSS Percentile 96.1%

Details

CWE
CWE-94
Status published
Products (4)
microsoft/windows_server_2003
microsoft/windows_server_2008 (4 CPE variants)
microsoft/windows_vista (2 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Sep 15, 2010
Tracked Since Feb 18, 2026