vendor:
Windows Media Player
by:
Jelmer Kuperus
7.5
CVSS
HIGH
Code Execution
94
CWE
Product Name: Windows Media Player
Affected Version From: Windows Media Player 8
Affected Version To: Windows Media Player 8
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:windows_media_player:8.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP English and Dutch
2002
Windows Media Player Code Execution Vulnerability
Windows Media Player is vulnerable to code execution through skin files. WMP does not properly validate URLs that are passed to initiate a skin file download and installation. This could allow a malicious file advertised as a skin file to be downloaded to a known location and executed through some other means.
Mitigation:
Validate URLs that are passed to initiate a skin file download and installation.