vendor:
Windows Media Center
by:
Eduardo Braun Prado
9,3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Windows Media Center
Affected Version From: MS Windows Media Center latest version on any Windows OS.
Affected Version To: MS Windows Media Center latest version on any Windows OS.
Patch Exists: Yes
Related CWE: CVE-2015-6131
CPE: o:microsoft:windows_media_center
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Microsoft Windows Media Center Library Parsing RCE Vuln aka ‘self-executing’ MCL file (CVE-2015-6131)
Windows Media Center contains a remote code execution vulnerability because it allows 'MCL' files to reference themselves as HTML pages, which will be parsed inside Windows Media Center window, in the context of the local machine security zone of Internet Explorer browser. This in turn allows execution of arbitrary code using eg. ADO ActiveX Objects. AKA 'self-executing' MCL files.
Mitigation:
Microsoft has released a security update to address this vulnerability.