Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
BID:10693
Info
Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
| Bugtraq ID: | 10693 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0726 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Paul <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
Microsoft Windows 2000 is reported prone to a script code execution vulnerability. Specifically, this issue arises when a user previews media in Windows Explorer.
It is reported that malicious script code can be executed in the local zone when files in a specially crafted play list are previewed. This can be exploited by specifying the 'javascript:' protocol for one or more of the files.
This issue can be leveraged to carry out various attacks.
Microsoft Windows 2000 is reported prone to a script code execution vulnerability. Specifically, this issue arises when a user previews media in Windows Explorer.
It is reported that malicious script code can be executed in the local zone when files in a specially crafted play list are previewed. This can be exploited by specifying the 'javascript:' protocol for one or more of the files.
This issue can be leveraged to carry out various attacks.
Exploit / POC
Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
A proof of concept is available from the following location:
http://freehost07.websamba.com/greyhats/asxvuln.htm
A proof of concept is available from the following location:
http://freehost07.websamba.com/greyhats/asxvuln.htm
Solution / Fix
Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
References:
References: