This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Windows Media Player v9, v10 Vuln - patch available

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/22971/
Release Date: 2006-12-08
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Unpatched
Software: Microsoft Windows Media Player 10.x…
…Successful exploitation crashes the program and may potentially allow execution of arbitrary code, though this has not currently been proven. The vulnerability is reported in version 10.00.00.4036. Other versions may also be affected.
Solution: Do not open untrusted playlists…"

:(
Also WMP v9:

- http://www.computerworld.com/action/articl…rce=rss_topic85
December 08, 2006
"…Affects Windows Media Player Versions 9 and 10, could allow a malicious hacker to run unauthorized software on a victim's PC or cause a denial-of-service attack… The flaw is due to a buffer overflow error that can occur when Windows Media Player is used to run .asx media files, according to a warning from eEye Digital Security*. Such files open automatically in a Web browser, meaning a hacker would need only to post an infected .asx file in a Web page and then try to lure users to visit the page, eEye Digital said. An infected file could also be sent via e-mail, in which case users would need to be persuaded to open it…"
* http://research.eeye.com/html/alerts/zeroday/20061122.html
Common Name: ASX Playlist
Date Disclosed: 11/22/2006
Expected Patch Release: Unknown
Vendor: Microsoft
Application: Windows Media Player
Description: "…function at 7D7A8F27 in WMVCORE.DLL version 9.0.0.3250, and at 086E586E in WMVCORE.DLL version 10.0.0.3802…"
Severity: High …

- http://blogs.technet.com/msrc/archive/2006…mat-isssue.aspx
December 07, 2006
"…We’re aware of proof-of-concept code published publicly affecting Windows Media ASX file format. We are currently investigating this report. We are not currently aware of attempts to exploit this vulnerability. The ASX file format is an XML-based media file format which is processed by Windows Media Player. An attacker could construct a malformed ASX file and use it to cause Media Player to overrun a heap-allocated buffer, potentially leading to remote code execution. We are also investigating other attack vectors to reach the same vulnerable code…"

:ph34r: