CVE-2003-0604
Summary
| CVE | CVE-2003-0604 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-08-27 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Windows Media Player | 7 | All | All | All |
| Application | Microsoft | Windows Media Player | 8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.malware.com/once.again%21.html | af854a3a-2127-422b-91ae-364da2661108 | www.malware.com | |
| www.pivx.com/larholm/unpatched | af854a3a-2127-422b-91ae-364da2661108 | www.pivx.com | |
| 'Re: Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'RE: Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| MISC:http://www.malware.com/once.again!.html | MITRE | www.malware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.