vendor:
DXMedia SDK
by:
Krystian Kloskowski (h07) <h07@interia.pl>
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: DXMedia SDK
Affected Version From: Microsoft DXMedia SDK 6.0
Affected Version To: Microsoft DXMedia SDK 6.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows XP SP2 Polish + all patches
2007
Microsoft DXMedia SDK 6 “SourceUrl” ActiveX 0day Remote Code Execution Exploit
This exploit takes advantage of a vulnerability in Microsoft DXMedia SDK 6's ActiveX control called "SourceUrl". By setting the SourceUrl property to a specially crafted value, an attacker can execute arbitrary code on a vulnerable system. This exploit has been tested on Microsoft DirectX Media 6.0 SDK, Microsoft Internet Explorer 6 with all patches, and Microsoft Windows XP SP2 (Polish) with all patches.
Mitigation:
Apply the latest patches and updates from Microsoft to ensure the vulnerability is patched. Disable the ActiveX control if it is not necessary for your system.