PT-2008-6103 · Microsoft · Windows Media Player

Published

2008-11-04

·

Updated

2008-11-05

·

CVE-2008-4927

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows Media Player versions 9.0 through 11
Description The issue allows user-assisted attackers to cause a denial of service, resulting in an application crash, via a malformed MIDI or DAT file. This is related to MThd Header Parsing.
Recommendations For versions 9.0 through 11, avoid using the affected Microsoft Windows Media Player to open MIDI or DAT files from untrusted sources until a fix is available. As a temporary workaround, consider restricting the use of MIDI and DAT file playback in Microsoft Windows Media Player to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4927

Affected Products

Windows Media Player