Cyber Resilience

CVE-2012-0003

Microsoft Windows Server 2008 r2

High EPSS
Published
10 January 2012
Modified
11 April 2025
CVSS Score v3.1 8.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.69 99.3th percentile
Risk Priority 81 floored blend · peak EPSS

Summary

CVE-2012-0003 is a high-severity an unspecified weakness vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 8.1 (High).

Operationally, ranked in the top 0.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI…

more

file, aka "MIDI Remote Code Execution Vulnerability."

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1204.002 Malicious File Executionconfidence: HIGH
Remote code execution via a crafted MIDI file requires the user to open or play the malicious file.
T1203 Exploitation for Client Execution Executionconfidence: HIGH
The vulnerability is exploited when the crafted MIDI file is processed by Windows Media Player, enabling client-side code execution.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2010-4398Same product: Microsoft Windows 7
CVE-2012-0151Same product: Microsoft Windows 7
CVE-2011-3402Same product: Microsoft Windows 7
CVE-2010-2568Same product: Microsoft Windows 7
CVE-2011-0657Same product: Microsoft Windows 7
CVE-2010-3962Same product: Microsoft Windows 7
CVE-2012-4969Same product: Microsoft Windows 7
CVE-2012-4792Same product: Microsoft Windows 7
CVE-2013-1347Same product: Microsoft Windows 7
CVE-2013-0810Same product: Microsoft Windows Server 2003

Affected Assets

microsoft
windows 7
all versions
microsoft
windows server 2003
all versions
microsoft
windows server 2008
all versions, r2
microsoft
windows vista
all versions
microsoft
windows xp
2005, all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References