CERT-In Vulnerability Note
CIVN-2010-0200
Microsoft MPEG-4 codec Could Allow Remote Code Execution Vulnerability
Original Issue Date:September 16, 2010
Severity Rating: HIGH
Systems Affected
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Vista Service Pack 1 and Windows Vista Service
Pack 2 - Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Overview
A vulnerability has been reported in Microsoft MPEG-4 codec , successful exploitation of this vulnerability could allow an attacker to execute an arbitrary code and take complete control of the affected system in the context of logged in user.
Description
A remote code execution vulnerability exists in the Microsoft MPEG-4 codec while handling supported format files. An attacker could exploit the vulnerability by constructing a specially crafted media file using MPEG-4 video encoding. Opening this file results in remote code execution and could allow remote attacker to take complete control of the affected system if the user is logged with administrative privileges.
Workaround
- Restrict access to the MPEG-4 version 1 codec
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS10-062
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/ms10-062.mspx
References
Security Tracker
http://securitytracker.com/alerts/2010/Sep/1024436.html
Nessus
http://www.nessus.org/plugins/index.php?view=single&id=49220
CVE Name
CVE-2010-0818
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|