PT-2004-2248 · Microsoft · Windows Media Player

Arman Nayyeri

·

Publicado

2004-12-18

·

Atualizado

2017-07-11

·

CVE-2004-1325

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows Media Player version 9.0
Description: The issue allows remote attackers to determine the existence of files on the local system by utilizing the getItemInfoByAtom function in the ActiveX control, which returns a 0 if the file does not exist and the size of the file if the file exists.
Recommendations: For Microsoft Windows Media Player version 9.0, consider disabling the getItemInfoByAtom function as a temporary workaround until a patch is available. Restrict access to the ActiveX control to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1325

Produtos afetados

Windows Media Player