PT-2003-1741 · Microsoft · Windows Media Player
Thor Larholm
·
Published
2003-07-29
·
Updated
2018-08-13
·
CVE-2003-0604
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Windows Media Player versions 7 and 8
Description:
The issue allows remote attackers to bypass zone restrictions and access or execute arbitrary files. This is achieved via an IFRAME tag pointing to an ASF file whose Content-location contains a
File:// URL.Recommendations:
For Windows Media Player version 7, update to a version that is not affected by this issue.
For Windows Media Player version 8, update to a version that is not affected by this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows Media Player