Skip to main content

Microsoft Windows Media Remote Code Execution Vulnerability

Last Update Date: 14 Dec 2011 12:27 Release Date: 14 Dec 2011 4488 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A remote code execution vulnerability exists in the way that Windows Media Player and Windows Media Center handle .dvr-ms files. This vulnerability could allow an attacker to execute arbitrary code if the attacker convinces a user to open a specially crafted .dvr-ms file. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


Impact

  • Remote Code Execution

System / Technologies affected

  • Windows XP
  • Windows Vista
  • Windows 7

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link