Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/41093 - | |
References | () http://www.gnucitizen.org/blog/backdooring-windows-media-files - | |
References | () http://www.securityfocus.com/archive/1/479825/100/100/threaded - | |
References | () http://www.securityfocus.com/archive/1/479854/100/100/threaded - | |
References | () http://www.securityfocus.com/archive/1/479855/100/100/threaded - | |
References | () http://www.securityfocus.com/archive/1/479856/100/100/threaded - |
Information
Published : 2007-09-26 22:17
Updated : 2024-11-21 00:37
NVD link : CVE-2007-5095
Mitre link : CVE-2007-5095
CVE.ORG link : CVE-2007-5095
JSON object : View
Products Affected
microsoft
- windows_xp
- windows_media_player
CWE
CWE-20
Improper Input Validation