Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
BID:36644
Info
Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
| Bugtraq ID: | 36644 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2527 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2009 12:00AM |
| Updated: | Nov 02 2009 05:57PM |
| Credit: | Yamata Li of Palo Alto Networks |
| Vulnerable: |
Nortel Networks Self-Service WVADS 0 Nortel Networks Self-Service VoiceXML 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service CCXML 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Peri Workstation 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Windows Media Player 6.4 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
Microsoft Windows Media Player is prone to a remote code-execution vulnerability when handling specially crafted Advanced Systems Format (ASF) files.
An attacker can exploit this issue by enticing an unsuspecting user into opening a malicious file with the vulnerable application. A successful exploit will allow arbitrary code to run in the context of the currently logged-in user.
Microsoft Windows Media Player is prone to a remote code-execution vulnerability when handling specially crafted Advanced Systems Format (ASF) files.
An attacker can exploit this issue by enticing an unsuspecting user into opening a malicious file with the vulnerable application. A successful exploit will allow arbitrary code to run in the context of the currently logged-in user.
Exploit / POC
Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Media Player 6.4
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Media Player 6.4
-
Microsoft Security Update for Windows 2000 (KB974112)
http://www.microsoft.com/downloads/details.aspx?familyid=13035ef7-7e47 -487c-8b7c-7795d33ce7de -
Microsoft Security Update for Windows Server 2003 (KB974112)
http://www.microsoft.com/downloads/details.aspx?familyid=5f82d01c-573e -425e-b9f2-86a54f377b19 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB974112)
http://www.microsoft.com/downloads/details.aspx?familyid=65e9036e-2e1b -40ff-a84b-c507107bcce8 -
Microsoft Security Update for Windows XP (KB974112)
http://www.microsoft.com/downloads/details.aspx?familyid=b2efe1ac-d8d7 -41bb-b87d-fc5e22afef0f -
Microsoft Security Update for Windows XP x64 Edition (KB974112)
http://www.microsoft.com/downloads/details.aspx?familyid=a9e7dfd8-7ba1 -4f14-8e60-92ef00d91467
References
Microsoft Windows Media Player ASF File Processing Remote Code Execution Vulnerability
References:
References:
- Nortel Enterprise Response to Microsoft Security Bulletin MS09-052 (Nortel Networks)
- Windows Media Player Homepage (Microsoft)
- Microsoft Security Bulletin MS09-052 (Microsoft)