← All CVEs

CVE-2011-3401

high · 9.3

ENCDEC.DLL in Windows Media Player and Media Center in Microsoft Windows XP SP2 and SP3, Windows Vista SP2, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .dvr-ms file, aka "Windows Media Player DVR-MS Memory Corruption Vulnerability."

9.3
CVSS
20.7%
EPSS (exploit prob.)
97th
EPSS percentile
2011-12-14
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftwindows_7all versions
microsoftwindows_7all versions
microsoftwindows_7all versions
microsoftwindows_vistaall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xp2005

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-3401