Search:     Advanced search
server monitoring

DRM Update in Windows Media Player may facilitate spyware infections (892313)

Article ID: 18085
Last updated: 27 Jan, 2009
Views: 968
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

DRM Update in Windows Media Player may facilitate spyware infections (892313)

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyWindows : Microsoft Bulletins
Plugin ID18085
Bugtraq ID13607
CVE ID

Description:

Synopsis :

It is possible to install spyware on the remote host.

Description :

The remote host is running a version Windows Media Player 9 or Windows Media
Player 10 which contains a vulnerability which may allow an attacker to infect
the remote host with spyware.

An attacker may exploit this flaw by crafting malformed WMP files which will
cause Windows Media Player to redirect the users to a rogue website when
attempting to acquire a license to read the file.

Solution :

http://support.microsoft.com/kb/892313/

See also :

http://www.benedelman.org/news/010205-1.html

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Cumulative Security Update of ActiveX Kill Bits (950760)     Cumulative Security Update for Internet Explorer (916281)