PT-2013-4158 · Microsoft · Windows Media Player+1

Publicado

2013-07-10

·

Atualizado

2018-10-12

·

CVE-2013-3127

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Media Format Runtime versions 9 and 9.5 Windows Media Format Runtime 11 Windows Media Player versions 11 and 12
Description The issue allows remote attackers to execute arbitrary code via a crafted media file. This is related to the Microsoft WMV video codec in various Windows Media Format Runtime and Windows Media Player versions.
Recommendations For Windows Media Format Runtime versions 9 and 9.5, consider disabling the use of the WMV video codec until a patch is available. For Windows Media Format Runtime 11, restrict access to media files to minimize the risk of exploitation. For Windows Media Player versions 11 and 12, avoid playing crafted media files in the affected player until the issue is resolved.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3127
ZDI-13-168

Produtos afetados

Windows Media Format Runtime
Windows Media Player