PT-2004-2248 · Microsoft · Windows Media Player
Arman Nayyeri
·
Publicado
2004-12-18
·
Atualizado
2017-07-11
·
CVE-2004-1325
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows Media Player version 9.0
Description:
The issue allows remote attackers to determine the existence of files on the local system by utilizing the getItemInfoByAtom function in the ActiveX control, which returns a 0 if the file does not exist and the size of the file if the file exists.
Recommendations:
For Microsoft Windows Media Player version 9.0, consider disabling the getItemInfoByAtom function as a temporary workaround until a patch is available. Restrict access to the ActiveX control to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows Media Player