CERT-In Vulnerability Note
CIVN-2007-0156
Microsoft Windows Media File Format Remote Code Execution vulnerability
Original Issue Date:December 12, 2007
Severity Rating: MEDIUM
Systems Affected
- Windows Media Format Runtime 7.1
- Windows Media Format Runtime 9
- Windows Media Format Runtime 9.5
- Windows Media Format Runtime 9.5 x64 Edition
- Windows Media Format Runtime 11
- Windows Media Services 9.1
Overview
A vulnerability has been reported in Microsoft Windows Media Format Runtime due to the way it handles Advanced Systems Format ASF
Description
The Microsoft Windows Media Format Runtime provides information and tools for applications that use Windows Media content. ASF Advanced Systems Format is a file format that stores audio and video information and is specially designed to run over networks like the Internet. It is a compressed format that contains streaming audio, video, slide shows, and synchronized events.
This vulnerability is caused due to incorrect parsing of ASF files within the Windows Media Format Runtime, which could be exploited by remote attacker to execute arbitrary code by tricking a user to visit a specially crafted web page.
Workaround
- For client applications deny access to WMASF.DLL
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS07-068
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS07-068.mspx
References
Frsirt
http://www.frsirt.com/english/advisories/2007/4183
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS07-068.mspx
Secunia
http://secunia.com/advisories/28034/
Security Tracker
http://www.securitytracker.com/alerts/2007/Dec/1019074.html
ISS
http://www.iss.net/threats/279.html
CVE Name
CVE-2007-0064
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|