Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
BID:57857
Info
Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
| Bugtraq ID: | 57857 |
| Class: | Unknown |
| CVE: |
CVE-2013-0077 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2013 12:00AM |
| Updated: | Apr 02 2013 11:07AM |
| Credit: | Tencent Security Team |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
Microsoft DirectShow is prone to a remote code-execution vulnerability.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running an application that uses DirectShow. Failed exploit attempts will result in a denial-of-service condition.
Microsoft DirectShow is prone to a remote code-execution vulnerability.
Successful exploits allow remote attackers to execute arbitrary code in the context of the user running an application that uses DirectShow. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
A commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft DirectShow CVE-2013-0077 Remote Code Execution Vulnerability
References:
References:
- Microsoft DirectX Homepage (Microsoft)
- Microsoft Homepage (Microsoft)