PT-2009-4040 · Microsoft · Windows Server 2003+6
Vinay Anantharaman
·
Published
2009-08-12
·
Updated
2023-12-07
·
CVE-2009-1546
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Windows 2000 SP4
Windows XP SP2
Windows XP SP3
Windows Server 2003 SP2
Windows Vista Gold
Windows Vista SP1
Windows Vista SP2
Windows Server 2008 Gold
Windows Server 2008 SP2
Description:
A remote code execution issue exists in the way Microsoft Windows handles specially crafted AVI format files. This could allow code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, an attacker who successfully exploited this issue could take complete control of an affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The
Avifil32.dll is involved in this issue, specifically due to an integer overflow in the Windows Media file handling functionality.Recommendations:
For Windows 2000 SP4, update to a newer version to mitigate the risk.
For Windows XP SP2 and SP3, consider restricting access to AVI files until a patch is available.
For Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2, avoid opening specially crafted AVI files until the issue is resolved.
As a temporary workaround, consider disabling the handling of AVI files in Windows Media until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avifil32.Dll
Windows
Windows 2000
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp