vendor:
Windows Media Player
by:
Unknown
N/A
CVSS
CRITICAL
This exploit allows remote attackers to execute arbitrary code via a long string in the fileName parameter in a .avi file, which triggers a heap-based buffer overflow in the l3codeca.acm codec, aka “Windows Media Player MP3 Codec Vulnerability.”
119
CWE
Product Name: Windows Media Player
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2010-0480
CPE: a:microsoft:windows_media_player:11
Platforms Tested: Windows
Microsoft MPEG Layer-3 Remote Command Execution Exploit
This exploit allows remote attackers to execute arbitrary code via a long string in the fileName parameter in a .avi file, which triggers a heap-based buffer overflow in the l3codeca.acm codec, aka "Windows Media Player MP3 Codec Vulnerability."
Mitigation:
Apply the appropriate security update provided by Microsoft.