Microsoft Windows Media Products Code Execution Vulnerabilities (10 December 2008)
RISK: Medium Risk
1. SPN Vulnerability
A credential reflection vulnerability exists in the Windows Media components that could allow an attacker to execute code with the same rights as the local user or with Windows Media Services distribution credentials. The vulnerability exists due to weaknesses in Service Principal Name (SPN) implementations within Windows Media components.
2. ISATAP Vulnerability
An information disclosure vulnerability exists in supported versions of Windows Media components that could result in the disclosure of NTLM credentials. Any Windows Media component that accesses a URL that uses an ISATAP address could leak the user¡¦s NTLM credentials to the server that hosts the URL. This could allow an attacker who is external to the intranet zone to gather NTLM credentials for an enterprise environment.
Impact
- Remote Code Execution
System / Technologies affected
- Windows Media Player 6.4
- Windows Media Format Runtime 7.1
- Windows Media Format Runtime 9.0
- Windows Media Format Runtime 9.5
- Windows Media Format Runtime 11
- Windows Media Services
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Windows Media Player 6.4
Microsoft Windows 2000 Server Service Pack 4
Windows XP Service Pack 2 and Windows XP Service Pack 3
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
- Windows Media Format Runtime 7.1, Windows Media Format Runtime 9.0, Windows Media Format Runtime 9.5, and Windows Media Format Runtime 11
Microsoft Windows 2000 Service Pack 4 - Windows Media Format Runtime 7.1 and Windows Media Format Runtime 9.0
Windows XP Service Pack 2 - Windows Media Format Runtime 9.0, Windows Media Format Runtime 9.5, and Windows Media Format Runtime 11
Windows XP Service Pack 3 - Windows Media Format Runtime 9.0, Windows Media Format Runtime 9.5, and Windows Media Format Runtime 11
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Format Runtime 9.5 and Windows Media Format Runtime 11
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Format Runtime 9.5 x64 Edition
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Format Runtime 11 x64 Edition
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Windows Media Format Runtime 9.5
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Media Format Runtime 9.5
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Media Format Runtime 9.5 x64 Edition
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Media Format Runtime 11 x64 Edition
Windows Vista and Windows Vista Service Pack 1 - Windows Media Format Runtime 11
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 - Windows Media Format Runtime 11
Windows Server 2008 for 32-bit Systems - Windows Media Format Runtime 11
Windows Server 2008 for x64-based Systems - Windows Media Format Runtime 11
- Windows Media Services
Microsoft Windows 2000 Server Service Pack 4
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems
Windows Server 2008 for x64-based Systems
Vulnerability Identifier
Source
Related Link
Share with