CERT-In Vulnerability Note
CIVN-2010-0256
Remote Code Execution Vulnerability in Microsoft Windows Movie Maker
Original Issue Date:December 15, 2010
Severity Rating: MEDIUM
Systems Affected
- Windows Vista Service Pack 1 and Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
Component Affected
Overview
A remote code execution vulnerability has been reported in Microsoft Movie Maker which could allow a remote attacker to execute arbitrary code and take complete control of the affected system in the context of logged in user.
Description
Windows Movie Maker is an application that allows user to create, edit and add special effects to home movies.
This vulnerability exists in Microsoft Movie Maker in the way it handles the loading of DLL files . A remote user can create a specially crafted DLL file on a remote share (e.g., WebDAV, SMB share) and convince the user to open the specially crafted file. Successful exploitation of this vulnerability could allow an attacker to execute an arbitrary code and take complete control the affected system in the context of the logged in user.
Workaround
- Disable loading of libraries from WebDAV and remote network shares
- Disable the WebClient service
- Block TCP ports 139 and 445 at the firewall
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS10-093
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS10-093.mspx
References
Microsoft
http://support.microsoft.com/kb/2424434
http://www.microsoft.com/technet/security/Bulletin/MS10-093.mspx
VUPEN Security
www.vupen.com/english/Reference-CVE-2010-3967.php
SecurityFocus
http://www.securityfocus.com/bid/40446/
SecurityTracker
http://securitytracker.com/alerts/2010/Dec/1024875.htmlSecurityTracker
CVE Name
CVE-2010-3967
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|