PT-2008-4441 · Microsoft · Windows Media Services+2

Published

2008-12-10

·

Updated

2023-12-07

·

CVE-2008-3009

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Media Player version 6.4 Windows Media Format Runtime versions 7.1 through 11 Windows Media Services versions 4.1, 9, and 2008
Description The issue arises from improper use of the Service Principal Name (SPN) identifier when validating replies to authentication requests. This allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection.
Recommendations For Microsoft Windows Media Player version 6.4, update to a version that properly validates SPN identifiers. For Windows Media Format Runtime versions 7.1 through 11, apply configuration changes to correctly use SPN identifiers. For Windows Media Services versions 4.1, 9, and 2008, restrict access to authentication requests to prevent NTLM credential reflection.

Fix

Weakness Enumeration

Related Identifiers

CVE-2008-3009

Affected Products

Windows Media Format Runtime
Windows Media Player
Windows Media Services