Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:31065
Info
Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 31065 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3008 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2008 12:00AM |
| Updated: | Sep 25 2008 06:59PM |
| Credit: | Nguyen Minh Duc and Le Manh Tung with Bach Khoa Internetwork Security Center (BKIS) Hanoi University of Technology (Vietnam) |
| Vulnerable: |
Nortel Networks Self-Service WVADS 0 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service CCXML 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self Service VoiceXML 0 Nortel Networks Multimedia Comm MCS5100 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Microsoft Windows Media Encoder 9 x64 Microsoft Windows Media Encoder 9 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to open a malicious web document.
The following proof of concept and exploit are available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms08_053.tar.gz
https://www.immunityinc.com/downloads/immpartners/ms08_053-2.tar.gz
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
NOTE: Symantec has detected active in-the-wild exploits of this issue.
The following exploit code is available:
To exploit this issue an attacker must entice an unsuspecting user to open a malicious web document.
The following proof of concept and exploit are available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms08_053.tar.gz
https://www.immunityinc.com/downloads/immpartners/ms08_053-2.tar.gz
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
NOTE: Symantec has detected active in-the-wild exploits of this issue.
The following exploit code is available:
Solution / Fix
Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Media Encoder 9
Microsoft Windows Media Encoder 9 x64
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Windows Media Encoder 9
-
Microsoft Security Update for Windows Media Encoder 9 Series for Windows 2000 (KB954156)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0cabfbc0-db5d -4a6a-a4cd-e6df89ac2b25 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Server 2003 (KB954156)
Windows Server 2003 Service Pack 1; Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyID=54ce1080-94cf -4e4f-8e09-a7dbab2757c5 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Server 2008 (KB954156)
Windows Server 2008
http://www.microsoft.com/downloads/details.aspx?FamilyID=5434ca66-5a6b -4517-92fb-72dea0a172ec -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Vista (KB954156)
Windows Vista; Windows Vista Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyID=99beebc4-553a -46f8-8245-e3d932306c93 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows XP
Windows XP Service Pack 2 and Windows XP Service Pack 3
http://www.microsoft.com/downloads/details.aspx?FamilyID=57bcb3c2-49d3 -4f18-8d03-36abd03d7403
Microsoft Windows Media Encoder 9 x64
-
Microsoft Security Update for 32-bit Windows Media Encoder 9 Series for Windows Server 2003 x64 Edition (KB954
Windows Server 2003 Service Pack 2 x64 Edition; Windows Server 2003, Datacenter x64 Edition; Windows Server 2003, Enterprise x64 Edition; Windows Server 2003, Standard x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyID=c83011cd-90b8 -494c-9cad-fa055e101992 -
Microsoft Security Update for 32-bit Windows Media Encoder 9 Series for Windows XP x64 Edition (KB954156)
Windows Server 2003 Service Pack 2 x64 Edition; Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyID=18efea9e-b103 -46de-90d9-5e295854cec3 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Server 2003 x64 Edition (KB954156)
Windows Server 2003 Service Pack 2 x64 Edition; Windows Server 2003, Datacenter x64 Edition; Windows Server 2003, Enterprise x64 Edition; Windows Server 2003, Standard x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=d8f1b782-136b -443f-b5f2-63aa4d1fd94a -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Server 2008 for x64 Edition (KB954156
Windows Server 2008
http://www.microsoft.com/downloads/details.aspx?FamilyId=e30f9427-26d0 -4e86-b9b8-bc637c3b5734 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows Vista for x64-based Systems (KB954156
Windows Vista 64-bit Editions Service Pack 1; Windows Vista Business 64-bit edition; Windows Vista Enterprise 64-bit edition; Windows Vista Home Basic 64-bit edition; Windows Vista Home Premium 64-bit edition; Windows Vista Ultimate 64-bit edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=54d1279a-7f26 -4727-a39d-5505bcd4fc53 -
Microsoft Security Update for Windows Media Encoder 9 Series for Windows XP x64 Edition
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=ebc1737c-6e78 -4244-a1b2-a56d031f16e9
References
Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Windows Media Encoder Product Page (Microsoft)
- Microsoft Security Bulletin MS08-053 (Microsoft)
- Nortel Networks Security Advisory 2008009061 (Nortel Networks)
- Vulnerability Note VU#996227 Windows Media Encoder WMEX.DLL ActiveX Control buff (US-CERT)