vendor:
Windows Media Player
by:
Code Audit Labs
7,5
CVSS
HIGH
Remote Denial of Service
400
CWE
Product Name: Windows Media Player
Affected Version From: Windows Media Player 10.00.00.3998 quartz.dll 6.5.3790.4283
Affected Version To: Windows Media Player 11.0.5721.5230 quartz.dll 6.5.2600.5596
Patch Exists: YES
Related CWE: Please assign to this a CVE id
CPE: a:microsoft:windows_media_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
MircoSoft_Media_player_quartz.dll_mid_remote_Dos POC
A vulnerability exists within the quartz.dll code processing RMID header. If the data_id is not 'data' and midi_size is 0xfffffff8, the code would fall into an infinite loop.
Mitigation:
Update to the latest version of Windows Media Player