vendor:
Windows Media Encoder
by:
Nguyen Minh Duc and Le Manh Tung
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows Media Encoder
Affected Version From: Windows Media Encoder
Affected Version To: Not specified
Patch Exists: YES
Related CWE: CVE-2008-2250
CPE: a:microsoft:windows_media_encoder
Platforms Tested: Windows XP SP2 with Internet Explorer 6.0 SP2
2008
MS08-053 Windows Media Encoder wmex.dll ActiveX Control Buffer Overflow
This exploit allows for the execution of arbitrary code on Windows XP SP2 with Internet Explorer 6.0 SP2. It takes advantage of a buffer overflow vulnerability in the Windows Media Encoder's wmex.dll ActiveX control.
Mitigation:
Apply the patch provided by Microsoft in the MS08-053 security bulletin.