CERT-In Vulnerability Note
CIVN-2010-0233
Microsoft Windows Media Player Vulnerability
Original Issue Date:October 15, 2010
Severity Rating: MEDIUM
Systems Affected
- Windows XP SP 3
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP 2
- Windows Vista SP 1 and SP2
- Windows Vista x64 Edition SP 1 and SP 2
- Windows Server 2008 for 32-bit Systems and SP2
- Windows Server 2008 for x64-based Systems and SP2
- Windows 7 for 32-bit Systems
- Windows 7 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems
Component Affected
- Microsoft Windows Media Player 9.0 series
- Microsoft Windows Media Player 10.0
- Microsoft Windows Media Player 11.0
- Microsoft Windows Media Player 12.0
Overview
A vulnerability has been reported in Microsoft Windows Media Player that could allow an remote attacker to execute arbitrary code with the privileges of the logged in user.
Description
This vulnerability occurs in the Windows Media Player, it deallocates objects during a reload operation via a Web browser.
A remote attacker could exploit this vulnerability by creating a specially crafted media content, then entice users to visit the Web site and click a link in an e-mail message or Instant Messenger message that takes users to the attackers Web site.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code and take complete control of the affected system in the context of logged-in user.
Workaround
Solution
Apply patches as mentioned in Microsoft Security bulletin
MS10-082
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/ms10-082.mspx
References
Microsoft
http://www.microsoft.com/technet/security/bulletin/ms10-082.mspx
Security Tracker
http://securitytracker.com/alerts/2010/Oct/1024550.html
SecurityFocus
http://www.securityfocus.com/bid/43772/
CVE Name
CVE-2010-2745
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|