PT-2015-2955 · Microsoft · Windows 8+4
Francisco Falcon
+1
·
Published
2015-12-09
·
Updated
2019-05-15
·
CVE-2015-6127
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows Media Center versions in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1
Description
The issue allows remote attackers to read arbitrary files via a crafted .mcl file. It is related to insufficient processing of video files in the Windows operating system.
Recommendations
For Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1, consider restricting access to .mcl files until a patch is available.
As a temporary workaround, avoid using crafted .mcl files to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows 7
Windows 8
Windows 8.1
Windows Media Center
Windows Vista