vendor:
Windows media player
by:
SYS 49152
9
CVSS
CRITICAL
Stack Overflow
CWE
Product Name: Windows media player
Affected Version From: Windows media player 6.4
Affected Version To: Windows media player 6.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 ENG
Windows media player 6.4 MP4 Stack Overflow
This exploit is a stack overflow vulnerability in Windows media player 6.4 MP4 codec. It allows an attacker to execute arbitrary code on a vulnerable system. The exploit has been discovered and exploited by SYS 49152.
Mitigation:
Install the latest 3ivx codec version (5.0.1) or use an alternative media player.