Windows Media Player Playlist HTML Script Execution Vulnerability
BID:5110
Info
Windows Media Player Playlist HTML Script Execution Vulnerability
| Bugtraq ID: | 5110 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0615 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Microsoft credits Elias Levy with the discovery of this issue. |
| Vulnerable: |
Microsoft Windows Media Player XP Microsoft Windows Media Player 7.1 Microsoft Windows Media Player 6.4 |
| Not Vulnerable: | |
Discussion
Windows Media Player Playlist HTML Script Execution Vulnerability
Microsoft Windows Media Player is distributed with multiple versions of the Microsoft Windows Operating System. A vulnerability has been reported affecting systems using Windows Media Player 6.4, 7.1, or Media Player for Windows XP
A script execution vulnerability may allow an attacker to execute HTML scripts on the system under the context of the user. These scripts can perform any action that the user would be able to including modifying security settings, adding and deleting files. The flaw lies in the processing of a playlist that is saved after exiting.
Attackers are able to cause Media Player to store unescaped HTML input in a known location on the local drive. If this content is interpreted as HTML, included script code may execute within the Local Computer security zone.
Microsoft Windows Media Player is distributed with multiple versions of the Microsoft Windows Operating System. A vulnerability has been reported affecting systems using Windows Media Player 6.4, 7.1, or Media Player for Windows XP
A script execution vulnerability may allow an attacker to execute HTML scripts on the system under the context of the user. These scripts can perform any action that the user would be able to including modifying security settings, adding and deleting files. The flaw lies in the processing of a playlist that is saved after exiting.
Attackers are able to cause Media Player to store unescaped HTML input in a known location on the local drive. If this content is interpreted as HTML, included script code may execute within the Local Computer security zone.
Solution / Fix
Windows Media Player Playlist HTML Script Execution Vulnerability
Solution:
Microsoft has released a cumulative patch for Windows Media Player:
Microsoft Windows Media Player 7.1
Microsoft Windows Media Player 6.4
Microsoft Windows Media Player XP
Solution:
Microsoft has released a cumulative patch for Windows Media Player:
Microsoft Windows Media Player 7.1
-
Microsoft wm320920_71
http://download.microsoft.com/download/winmediaplayer/Update/320920/W9 82KMe/EN-US/wm320920_71.exe
Microsoft Windows Media Player 6.4
-
Microsoft wm320920_64
http://download.microsoft.com/download/winmediaplayer/Update/320920/W9 8NT42KMe/EN-US/wm320920_64.exe
Microsoft Windows Media Player XP
References
Windows Media Player Playlist HTML Script Execution Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-032 (Microsoft)