A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage.
The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1028, CVE-2020-1126, CVE-2020-1136. | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. |
| Title | Media Foundation Memory Corruption Vulnerability | |
| First Time appeared |
Microsoft windows Server 2008 R2
|
|
| CPEs | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:* |
|
| Vendors & Products |
Microsoft windows Server 2008 R2
|
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:33:45.160Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1150
No data.
Status : Modified
Published: 2020-05-21T23:15:16.993
Modified: 2026-08-19T17:17:24.367
Link: CVE-2020-1150
No data.
OpenCVE Enrichment
No data.