PT-2001-1381 · Microsoft · Windows Media Player+1

Publicado

2001-05-07

·

Atualizado

2018-10-12

·

CVE-2001-0148

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Windows Media Player version 7
Description: The issue allows remote attackers to execute commands in Internet Explorer via javascript URLs, related to the WMP ActiveX Control. This is a variant of the "Frame Domain Verification" issue.
Recommendations: For Windows Media Player version 7, consider disabling the WMP ActiveX Control as a temporary workaround until a patch is available. Restrict access to javascript URLs in Internet Explorer to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0148

Produtos afetados

Internet Explorer
Windows Media Player