CVE-2015-1728: Microsoft Windows Media Player
High severity, CVSS 9.3. EPSS: 17.6% chance of exploitation in the next 30 days.
Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject Vulnerability."
Affected products
- Microsoft Windows Media Player: version 10 only; version 10.00.00.3646 only; version 10.00.00.3990 only; version 10.00.00.4019 only; version 10.00.00.4036 only; version 11 only; …
Published 2015-06-10. Last modified 2026-06-17.