Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
CVSS Vector
AV:N/AC:M/Au:N/C:C/I:C/A:CMicrosoft Windows 2000
OSMicrosoftall versionsMicrosoft Windows Media Player
APPMicrosoft9Microsoft Windows Xp
OSMicrosoftall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
References
Related vulnerabilities
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE
CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
CVE-2019-5620CRITICAL9.8PL ✓same product
Brak uwierzytelnienia dla krytycznej funkcji w ABB MicroSCADA Pro SYS600
CVE-2020-7485CRITICAL9.8PL ✓same product
Ukryte konto serwisowe w Schneider Electric TriStation umożliwia nieautoryzowany dostęp
CVE-2012-1891CRITICAL9.8PL ✓same product
RCE w Microsoft MDAC/WDAC — heap buffer overflow przez dane XML