vendor:
Media Player Classic
by:
Gjoko 'LiquidWorm' Krstic
N/A
CVSS
N/A
DLL Hijacking
N/A
CWE
Product Name: Media Player Classic
Affected Version From: 6.4.9.1
Affected Version To: 6.4.9.1
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2010
Media Player Classic 6.4.9.1 (iacenc.dll) DLL Hijacking Exploit
Media Player Classic (MPC) is a compact media player for 32-bit Microsoft Windows. The application mimics the look and feel of the old, lightweight Windows Media Player 6.4 but integrates most options and features found in modern media players. It and its forks are standard media players in the K-Lite Codec Pack and the Combined Community Codec Pack. Media Player Classic suffers from a dll hijacking vulnerability that enables the attacker to execute arbitrary code on a local level. The vulnerable extensions are .mka, .ra and .ram thru iacenc.dll library.
Mitigation:
N/A