PT-2008-6103 · Microsoft · Windows Media Player
Published
2008-11-04
·
Updated
2008-11-05
·
CVE-2008-4927
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Media Player versions 9.0 through 11
Description
The issue allows user-assisted attackers to cause a denial of service, resulting in an application crash, via a malformed MIDI or DAT file. This is related to MThd Header Parsing.
Recommendations
For versions 9.0 through 11, avoid using the affected Microsoft Windows Media Player to open MIDI or DAT files from untrusted sources until a fix is available. As a temporary workaround, consider restricting the use of MIDI and DAT file playback in Microsoft Windows Media Player to minimize the risk of exploitation.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Media Player