vendor:
Windows Media Player
by:
ATmaCA
9.3
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Windows Media Player
Affected Version From: Windows Media Player 7.1
Affected Version To: Windows Media Player 10
Patch Exists: YES
Related CWE: CVE-2006-0003
CPE: a:microsoft:windows_media_player
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/browser/ie_createobject, https://www.infosecmatter.com/nessus-plugin-library/?id=43836, https://www.infosecmatter.com/nessus-plugin-library/?id=43839, https://www.infosecmatter.com/nessus-plugin-library/?id=41187, https://www.infosecmatter.com/nessus-plugin-library/?id=43838, https://www.infosecmatter.com/nessus-plugin-library/?id=22612, https://www.infosecmatter.com/nessus-plugin-library/?id=35684, https://www.infosecmatter.com/nessus-plugin-library/?id=35323, https://www.infosecmatter.com/nessus-plugin-library/?id=29723, https://www.infosecmatter.com/nessus-plugin-library/?id=31147
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT 4.0, Windows 98 / ME, Windows 2000 SP4, Windows XP SP1 / SP2, Windows 2003
2006
Windows Media Player BMP Heap Overflow (MS06-005)
In this vulnerability, payload is loaded to different places in memory each time. A crafted BMP file is created which when opened in Windows Media Player 7.1 through 10, can lead to a heap overflow vulnerability.
Mitigation:
Microsoft has released a patch for this vulnerability.