vendor:
Windows Media Player
by:
Nicolas Krassas
7.5
CVSS
HIGH
Denial of Service (DOS)
400
CWE
Product Name: Windows Media Player
Affected Version From: Windows Media Player 12
Affected Version To: Windows Media Player 12
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:windows_media_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2011
Windows Media Player with klite codec pack DOS Poc
The 3gp handling from MP4Splitter.ax filter of klite codec pack will cause an Access violation when a specially crafted movie file is loaded on the media player. The same crash will occur also when the file is loaded on a playlist and the media player will try to generate thumbnail image of the contents.
Mitigation:
Update the klite codec pack to the latest version.