Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
BID:42855
Info
Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42855 |
| Class: | Design Error |
| CVE: |
CVE-2010-3965 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2010 12:00AM |
| Updated: | Dec 16 2010 07:14PM |
| Credit: | Venom23 |
| Vulnerable: |
Microsoft Windows Media Encoder 9.00.00.2980 Microsoft Windows Media Encoder 9 x64 Microsoft Windows Media Encoder 9 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Enterprise Edition Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
Microsoft Windows Media Encoder 9 is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Microsoft Windows Media Encoder 9 is vulnerable; other versions may also be affected.
Microsoft Windows Media Encoder 9 is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Microsoft Windows Media Encoder 9 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
Attackers must trick a user into opening a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Attackers must trick a user into opening a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Media Encoder 9
Microsoft Windows Media Encoder 9 x64
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Media Encoder 9
-
Microsoft WindowsMedia9-x86-KB2447961-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=DC777E61-E1E3 -43BF-A84D-22C4A69C135D -
Microsoft WindowsMedia9-KB2447961-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=EF0ADA2C-965F -438F-A1D3-BD45DB8460C1 -
Microsoft WME09-KB2447961.x86fre.usa.exe
http://www.microsoft.com/downloads/details.aspx?familyid=E8A57950-43CD -486F-BD97-70B0AD360A0B
Microsoft Windows Media Encoder 9 x64
-
Microsoft WME9-x64-KB2447961.exe
http://www.microsoft.com/downloads/details.aspx?familyid=E1054088-F484 -4F44-BA0E-5CBD21773C0C -
Microsoft WindowsMedia9-KB2447961-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=550957C2-CE66 -439F-95EA-681237513F75
References
Microsoft Windows Media Encoder 9 DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Windows Media Encoder 9 Series (Microsoft)
- Avaya ASA-2010-352 MS10-094 Vulnerability in Windows Media Encoder Could Allow R (Avaya)
- Microsoft Security Advisory (2269637) (Microsoft)
- Microsoft Security Bulletin MS10-094 (Microsoft)