Error » Microsoft Error! » Microsoft live error » Security Hole Discovered in Microsoft Windows Media Player

Post New Thread Reply
  Security Hole Discovered in Microsoft Windows Media Player
LinkBack Thread Tools Display Modes
Old 10-Dec-2006, 10:38 PM   #1 (permalink)
Administrator
 
Admin's Avatar

Posts: 876
Join Date: Oct 2005
Rep Power: 10 Admin has disabled reputation

IM:
Default Security Hole Discovered in Microsoft Windows Media Player

Users are being advised to disable a certain type of file in Microsoft’s Windows Media Player software following the discovery of a new security hole.
The flaw, which affects Windows Media Player versions 9 and 10, could allow a malicious hacker to run unauthorized software on a victim’s PC or cause a denial-of-service attack, according to security company FrSIRT, which rated the problem critical in an advisory Thursday.
The flaw is due to a buffer overflow error that can occur when Windows Media Player is used to run ".asx" media files, according to a warning from eEye Digital Security.
Such files open automatically in a Web browser, meaning a hacker would need only to post an infected .asx file in a webpage and then try to lure users to visit the page, eEye Digital said. An infected file could also be sent via e-mail, in which case users would need to be persuaded to open it.
Microsoft said an initial investigation revealed that the "proof-of-concept" code could allow an attacker to execute code on a user’s machine. It said it was unaware of any attempts to exploit the vulnerability, and it was unclear Friday morning if the proof-of-concept code it referred to was in the hands of hackers.
Users can protect against the vulnerability in Internet Explorer by preventing it from opening .asx files automatically. Turning off Active Scripting would also greatly reduce, but not eliminate, the risk, Microsoft said. FrSIRT also recommended that users upgrade to Windows Media Player 11, which it said is not affected.
Microsoft was still determining Friday whether it needed to issue an "out-of-cycle" security fix for the problem or patch it with its next monthly software update.
The flaw was originally reported on Nov. 22, when it was identified only as a denial-of-service issue.
Some discussion boards described the problem as a "zero-day exploit," although it was unclear if that was the case. Zero-day exploits occur when exploit code is released on the same day that a flaw is uncovered, giving users no time to protect themselves.
It’s been another busy week for Microsoft’s security teams. On Tuesday the company warned of an unpatched vulnerability in Word that had been the subject of what it called "limited attacks." And on Thursday it said it was readying several patches for Visual Studio and Windows that it plans to release next week.
The patches currently due for next week do not address the problems with Word and Windows Media Player.
Admin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible iPhone Security Hole to be Demonstrated in Las Vegas Anilrgowda Mac - Operating Systems and Applications Error 0 02-Aug-2007 12:21 AM
View media content using Windows Media Player Firefox Plug-in Anilrgowda Microsoft windows vista error 0 18-Jul-2007 12:00 AM
Problems setting up Windows Media Player as the default player for *.WAV files Anilrgowda Microsoft Windows xp error 1 15-Feb-2007 01:24 AM
Google Patch Security Hole Anilrgowda Search Engine Optimization 0 14-Jan-2007 11:39 PM
New Security Hole Discovered In Microsoft Word Anilrgowda Microsoft 0 07-Jan-2007 09:13 AM


All times are GMT -8. The time now is 12:57 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228