PT-2017-1628 · Microsoft · Windows 7+4
Hyp3Rlinx
+1
·
Published
2017-03-14
·
Updated
2017-08-16
·
CVE-2017-0045
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows DVD Maker versions in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2
Description
The issue is related to the improper parsing of crafted .msdvd files by Windows DVD Maker, allowing attackers to obtain information that could be used to compromise a target system. This could potentially lead to the exploitation of the system through specially crafted applications.
Recommendations
For Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows Dvd Maker
Windows Server 2008
Windows Vista