CERT-In Vulnerability Note
CIVN-2009-0111
Microsoft Windows Media Player 6.4 Heap Overflow Vulnerability
Original Issue Date:September 10, 2009
Severity Rating: HIGH
Systems Affected
Microsoft Windows Media Player 6.4 running on: - Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2 and Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
Overview
A vulnerability is reported in the way that Windows Media Player 6.4 opens specially crafted ASF file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. The impact of the exploitation will be less if a user is a normal user with restricted rights than that of a user who operate with administrative rights.
Description
1. Heap Overflow Vulnerability in Windows Media Player
This vulnerability exists in the way that Windows Media Player 6.4 opens specially crafted ASF file. This vulnerability could be exploited by an attacker when a user opens a specially crafted ASF file using Windows Media Player 6.4. An attacker who successfully exploited this vulnerability could take complete control of the vulnerable system.
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS09-052
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/ms09-052.mspx
References
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS09-047.mspx
Vupen Security
http://www.vupen.com/english/advisories/2009/2888
McAfee
http://vil.nai.com/vil/content/v_vul48133.htm
CVE Name
CVE-2009-2527
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|