PT-2005-3064 · Microsoft · Windows Media Player+1

Published

2005-10-11

·

Updated

2018-10-12

·

CVE-2005-2128

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Windows Media Player 9
Description: The issue allows remote attackers to write a null byte to arbitrary memory via a crafted AVI file. This is achieved by modifying the length value in the strn element of the AVI file, which is processed by the QUARTZ.DLL component in Microsoft Windows Media Player.
Recommendations: For Microsoft Windows Media Player 9, consider avoiding the use of AVI files from untrusted sources until a patch is available. As a temporary workaround, restrict the use of the QUARTZ.DLL component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2128

Affected Products

Windows Media Player
Quartz.Dll