CERT-In Vulnerability Note
CIVN-2015-0306
Multiple Vulnerabilities in Windows Media Center
Original Issue Date:December 09, 2015
Severity Rating: MEDIUM
Software Affected
- Windows Vista SP2 and x64 Edition SP2
- Windows 7 for 32-bit Systems SP1 and x64-based Systems SP1
- Windows 8 for 32-bit Systems and x64-based Systems
- Windows 8.1 for 32-bit Systems and x64-based Systems
Overview
Multiple vulnerabilities have been reported in Windows Media Center which could allow a remote attacker to execute an arbitrary code on the targeted system or obtain sensitive information.
Description
1. Media Center Library Parsing Remote Code Execution Vulnerability
(
CVE-2015-6131
)
A remote code execution vulnerability exists in Windows Media Center Library due to an error while parsing Media Center link (.mcl) files. A remote attacker could exploit this vulnerability by enticing the user to open a specially crafted link in an email or convince the user to open a compromised website which is hosting a malicious ".mcl"file. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code with the privileges of the current logged-in user.
2. Windows Media Center Information Disclosure Vulnerability
(
CVE-2015-6127
)
An information disclosure vulnerability exists in Windows Media Center Library due to an error while parsing Media Center link (.mcl) files. A remote attacker could exploit this vulnerability by enticing the user to open a specially crafted link in an email or convince the user to open a compromised website which is hosting a malicious ".mcl" file. Successful exploitation of this vulnerability could allow the attacker to disclose local file system information.
Workaround
- Unregister the MCL protocol handler
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS15-134
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-134.aspx
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-134.aspx
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=42412
http://tools.cisco.com/security/center/viewAlert.x?alertId=42411
Security Tracker
http://www.securitytracker.com/id/1034335
CVE Name
CVE-2015-6131
CVE-2015-6127
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|