PT-2011-2029 · Microsoft · Windows Vista+5
Published
2011-03-09
·
Updated
2023-12-07
·
CVE-2011-0032
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista SP1 and SP2
Microsoft Windows 7 Gold and SP1
Microsoft Windows Server 2008 R2 and R2 SP1
Microsoft Windows Media Center TV Pack for Windows Vista
Description
The issue allows local users to gain privileges via a Trojan horse DLL in the current working directory. This can be demonstrated by a directory containing specific file types such as Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg files. A remote code execution vulnerability exists in the way that Microsoft DirectShow handles the loading of DLL files, potentially allowing an attacker to take complete control of an affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Windows Vista SP1 and SP2, consider restricting access to the
DirectShow component until a patch is available.
For Microsoft Windows 7 Gold and SP1, avoid using the vulnerable DLL loading mechanism in DirectShow until the issue is resolved.
For Microsoft Windows Server 2008 R2 and R2 SP1, restrict the use of DirectShow to minimize the risk of exploitation.
For Microsoft Windows Media Center TV Pack for Windows Vista, disable the DirectShow functionality as a temporary workaround until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directshow
Windows
Windows 7
Windows Media Center Tv Pack
Windows Server 2008 R2
Windows Vista