PT-2014-1746 · Microsoft · Windows Media Center+1

Alisaesage

·

Publicado

2014-08-12

·

Atualizado

2019-05-14

·

CVE-2014-4060

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows Media Center versions prior to the fixed version
Description The issue allows remote attackers to execute arbitrary code. To exploit this, an attacker must convince a user to open a specially crafted Microsoft Office file. This is achieved through a use-after-free vulnerability in the MCPlayer.dll, specifically when a CSyncBasePlayer object is deleted, allowing for the execution of arbitrary code.
Recommendations For Windows Media Center, update to a version that includes the fix for the CSyncBasePlayer Use After Free issue. As a temporary workaround, consider restricting the use of Microsoft Office files from untrusted sources to minimize the risk of exploitation.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00762
BDU:2015-00765
BDU:2015-00766
CVE-2014-4060
ZDI-14-287

Produtos afetados

Office
Windows Media Center