PT-2010-2544 · Microsoft · Vista+5
Matthew Watchinski
·
Published
2010-09-15
·
Updated
2023-12-07
·
CVE-2010-0818
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Media codecs versions in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2
Description
A remote code execution issue exists due to improper handling of crafted media content with MPEG-4 video encoding. This could allow code execution if a user opens a specially crafted media file. An attacker who successfully exploits this issue could take complete control of an affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The impact may be less severe for users with fewer user rights on the system.
Recommendations
For Windows XP SP2 and SP3, update to address the issue.
For Server 2003 SP2, apply the necessary patch to resolve the vulnerability.
For Vista SP1 and SP2, install the available update to fix the issue.
For Server 2008 Gold and SP2, apply the required patch to mitigate the risk.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Server 2003
Server 2008
Vista
Windows
Windows Media Codecs
Windows Xp