vendor:
Windows Movie Maker
by:
KedAns-Dz
7.5
CVSS
HIGH
Stack-based buffer-overflow
CWE
Product Name: Windows Movie Maker
Affected Version From: Windows Movie Maker 2.1.4026
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
Windows Movie Maker 2.1 (Import AVI video) Stack Overflow
The Windows Movie Maker application fails to perform adequate boundary checks on user-supplied data, leading to a stack-based buffer-overflow vulnerability. This vulnerability can be exploited to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Apply the latest security patches and updates from the vendor. Avoid importing AVI files from untrusted sources.