Vulnerability record · CVE-2014-2671 · published 31 March 2014
CVE-2014-2671: Windows Media Player WAV file memory corruption
Microsoft · Windows Media Player
Windows Media Player 11.0.5721.5230 mishandles a crafted WAV file, causing memory corruption. The flaw is remotely reachable and can crash the player or possibly lead to further impact, though the record does not specify the full consequences.
Description
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is high, but the confirmed impact is denial of service and the record lacks patch and version detail.
What it is
Windows Media Player 11.0.5721.5230 mishandles a crafted WAV file, causing memory corruption. The flaw is remotely reachable and can crash the player or possibly lead to further impact, though the record does not specify the full consequences.
Impact
An attacker can crash Windows Media Player through memory corruption; the description also allows for unspecified other impact, but no code execution or data compromise is confirmed.
Attack surface
Reached by opening or playing a crafted WAV file, typically delivered by a remote attacker; the CVSS vector AV:N/AC:M/Au:N indicates network delivery, medium complexity, and no authentication, with user interaction implied by opening the file.
Exploitation
Public exploit references exist (Packet Storm, Exploit-DB, SecurityFocus), but the CVE is not in CISA KEV; EPSS is 0.46291 (98.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft patch for the affected Windows Media Player version if one is available; the record does not list a patch, so verify with the vendor.
- Restrict or block untrusted WAV file attachments and downloads at email and web gateways.
- Disable or remove Windows Media Player on systems that do not require it.
- Open media files only from trusted sources and avoid previewing unknown WAV files.
Detection
- Monitor for Windows Media Player crashes or abnormal process termination correlated with WAV file opens.
- Scan email and web proxy logs for WAV attachments or downloads from untrusted sources.
- Use endpoint detection to flag wmplayer.exe spawning or loading unexpected modules after opening a media file.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2671), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.