vendor:
Windows Media Player 7
by:
GFI
8.3
CVSS
HIGH
Arbitrary Code Execution
94
CWE
Product Name: Windows Media Player 7
Affected Version From: Windows ME (WMP7 is installed by default)
Affected Version To: Outlook 98
Patch Exists: Yes
Related CWE: N/A
CPE: o:microsoft:windows_me
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows ME, 95, 98, NT, 2000
2000
Microsoft Media Player 7 allows executation of Arbitrary Code
GFI, developer of email content checking & network security software, has recently discovered a security flaw within Windows Media Player which allows a malicious user to run arbitary code on a target machine as it attempts to view a website or an HTML E-mail. The problem is exploited by embedding a javascript (.js) file within a Media Player skin file (.wmz) which can also be embeded in a Windows Media Download file (.wmd). This does not require the user to run any attachments since the Media Player file is automatically executed using a iframe tag or a window.open() with in a <script> tag.
Mitigation:
Microsoft has released a patch to address this vulnerability.