This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS06-005 proof of concept exploit released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1126
Last Updated: 2006-02-16 04:03:36 UTC
"The proof of concept exploit for MS06-005 has been released. The exploit crafts a malicious BMP file to perform a buffer overflow in Media Player. Keeping in mind as Microsoft has pointed out that the exploiting factor can include other graphics file as well (such as .wmp), it's a good idea to get it patched ASAP."
>>> http://www.microsoft.com/technet/security/…n/MS06-005.mspx

:ph34r:
More…

- http://www.techweb.com/article/printableAr…_section=700028
February 16, 2006
"…"There are two exploits circulating," said Mike Puterbaugh, the vice president of marketing at eEye Digital Security, the Aliso Viejo, Calif.-based company which first uncovered the Media Player vulnerability. "One is somewhat minor, and can cause a denial-of-service, but the second we're taking far more seriously," said Puterbaugh. "It's 95 percent there as a propagated mass attack. "All the guy needs to do is add shell code to it to remotely exploit machines." The exploit, which was posted to the Bugtraq security mailing list is "minutes or days from being completed," Puterbaugh said. "The exploit hasn't been able to reliably write to the same part of memory every time, but once he gets that, it's game over"…"

:ph34r:
FYI…

Multiple Exploits available for MS06-005 and MS06-006
- http://isc.sans.org/diary.php?storyid=1129
Last Updated: 2006-02-17 13:28:51 UTC
"The 'sploit writers have been busy. In the last 24 hours a total of four exploits have been released - two each for MS06-005 and MS06-006.
MS06-005 - Vulnerability in Windows Media Player Could Allow Remote Code Execution
MS06-006 - Vulnerability in Windows Media Player Plug-in with Non-Microsoft Internet Browsers Could Allow Remote Code Execution …"

:ph34r: :ph34r:
FYI…

Symantec ThreatCon Level is 2
- http://www.sarc.com/#
"The ThreatCon remains at Level 2 in light of proof-of-concept exploits released Friday for Microsoft Security Bulletins MS06-005 (BID 16633) and MS06-006 (BID 16644). Customers are advised to install appropriate updates as soon as possible…"


:ph34r: