Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
BID:22938
Info
Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
| Bugtraq ID: | 22938 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-1492 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2007 12:00AM |
| Updated: | May 12 2015 07:33PM |
| Credit: | Micha³ Majchrowicz <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Gold 0 Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
Microsoft Windows is prone to a denial-of-service vulnerability.
A remote attacker may exploit this vulnerability by presenting a malicious WAV file to a victim user.
Successful exploits will result in excessive CPU consumption, effectively denying service.
Microsoft Windows is prone to a denial-of-service vulnerability.
A remote attacker may exploit this vulnerability by presenting a malicious WAV file to a victim user.
Successful exploits will result in excessive CPU consumption, effectively denying service.
Exploit / POC
Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
References:
References:
- [VulnWatch] Windows Multimedia mmioRead Denial of Service Vulnerability (Micha³ Majchrowicz)
- Microsoft Windows Homepage (Microsoft )