CVE-2009-2499

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability."

Published: 2009-09-08 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-2499 is rated Moderate Risk (63.2/100): CVSS High severity, with high exploitation likelihood (EPSS 30.75%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-2499

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-27 35.34% 30.75% -4.59%
2 2026-01-28 37.78% 35.34% -2.43%
3 2025-12-28 37.78%

Full EPSS history (31 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-2499

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.5 2.0 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
6.8 10.0 [email protected]

Weakness enumeration for CVE-2009-2499

Affected software / configurations for CVE-2009-2499

Vendor Product Version Raw CPE
microsoft windows_media_format_runtime 9.0 cpe:2.3:a:microsoft:windows_media_format_runtime:9.0:*:*:*:*:*:*:*
microsoft windows_2000 cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*
microsoft windows_media_format_runtime 9.5 cpe:2.3:a:microsoft:windows_media_format_runtime:9.5:*:*:*:*:*:*:*
microsoft windows_server_2003 cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
microsoft windows_xp cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*
microsoft windows_media_format_runtime 9.5 cpe:2.3:a:microsoft:windows_media_format_runtime:9.5:*:x64:*:*:*:*:*
microsoft windows_media_format_runtime 11 cpe:2.3:a:microsoft:windows_media_format_runtime:11:*:*:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:-:-:x32:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:-:-:x64:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:-:sp2:x64:*:*:*:*:*
microsoft windows_server_2008 cpe:2.3:o:microsoft:windows_server_2008:-:sp2:x86:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
microsoft windows_media_services 9.1 cpe:2.3:a:microsoft:windows_media_services:9.1:*:*:*:*:*:*:*
microsoft windows_server_2003 cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*
microsoft windows_media_services 2008 cpe:2.3:a:microsoft:windows_media_services:2008:*:*:*:*:*:*:*
microsoft windows_media_foundation cpe:2.3:a:microsoft:windows_media_foundation:-:*:*:*:*:*:*:*
microsoft windows_vista cpe:2.3:o:microsoft:windows_vista:-:-:x64:*:*:*:*:*

References for CVE-2009-2499

cvelogic Threat Intelligence