PT-2014-1746 · Microsoft · Windows Media Center+1

Alisaesage

·

Published

2014-08-12

·

Updated

2019-05-14

·

CVE-2014-4060

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows Media Center versions prior to the fixed version
Description The issue allows remote attackers to execute arbitrary code. To exploit this, an attacker must convince a user to open a specially crafted Microsoft Office file. This is achieved through a use-after-free vulnerability in the MCPlayer.dll, specifically when a CSyncBasePlayer object is deleted, allowing for the execution of arbitrary code.
Recommendations For Windows Media Center, update to a version that includes the fix for the CSyncBasePlayer Use After Free issue. As a temporary workaround, consider restricting the use of Microsoft Office files from untrusted sources to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00762
BDU:2015-00765
BDU:2015-00766
CVE-2014-4060
ZDI-14-287

Affected Products

Office
Windows Media Center