Windows Media Player Internet Shortcut Execution Vulnerability
BID:2765
Info
Windows Media Player Internet Shortcut Execution Vulnerability
| Bugtraq ID: | 2765 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2001 12:00AM |
| Updated: | May 23 2001 12:00AM |
| Credit: | Posted in a Microsoft Security Bulletin MS01-029 on May 23, 2001. |
| Vulnerable: |
Microsoft Windows Media Player 7.0 Microsoft Windows Media Player 6.4 |
| Not Vulnerable: | |
Discussion
Windows Media Player Internet Shortcut Execution Vulnerability
A flaw exists in the implementation of Windows Media Player which could disclose sensitive information to attackers.
WMP creates internet shortcuts in the temporary internet files folder on the user's local system. These files are also created with 'fixed', known filenames.
The WMP created shortcuts are opened in Local Computer Zone rather than the Internet Zone. HTML opened in this Security Zone has the ability to read arbitrary files on the filesystem, as well as send data to webservers.
A flaw exists in the implementation of Windows Media Player which could disclose sensitive information to attackers.
WMP creates internet shortcuts in the temporary internet files folder on the user's local system. These files are also created with 'fixed', known filenames.
The WMP created shortcuts are opened in Local Computer Zone rather than the Internet Zone. HTML opened in this Security Zone has the ability to read arbitrary files on the filesystem, as well as send data to webservers.
Solution / Fix
Windows Media Player Internet Shortcut Execution Vulnerability
Solution:
Microsoft has released a cumulative patch which rectifies this issue:
Microsoft Windows Media Player 6.4
Microsoft Windows Media Player 7.0
Solution:
Microsoft has released a cumulative patch which rectifies this issue:
Microsoft Windows Media Player 6.4
-
Microsoft wm308567
http://download.microsoft.com/download/winmediaplayer/Update/308567/WI N98MeXP/EN-US/wm308567.exe
Microsoft Windows Media Player 7.0