vendor:
Windows Media Player
by:
SecurityFocus
7.5
CVSS
HIGH
Injection of malicious script code
94
CWE
Product Name: Windows Media Player
Affected Version From: Windows Media Player 9
Affected Version To: Windows XP SP2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2004
Windows Media Player ActiveX Control Security Weakness
The Windows Media Player ActiveX control is prone to a security weakness. The issue is that the control may be abused by a Web page to change attributes of media files (such as MP3). An attacker can influence attributes such as the artist, song name, or album name. It is possible to exploit this weakness to inject malicious script code into these attributes. If this issue was combined with a vulnerability that could force Internet Explorer to interpret the injected script code, it may be possible to execute malicious script code in the Local Zone.
Mitigation:
Ensure that the Windows Media Player ActiveX control is not used in a Web page, or that the Local Zone is locked down.