Microsoft Disputes Claim of Windows Media Player Vulnerability
eWeek - RSS Feeds —
... the SANS Internet Storm Center Web site over the weekend stated a reader had tested proof-of-concept (POC) code on a fully patched Windows XP Service Pack 3 system and caused Windows Media Player 9 and 11 to crash. However, while Microsoft officials conceded the proof-of-concept code could trigger a crash, they found no possibility of arbitrary code execution. This particular crash is an unhandled CPU exception when executing a div instruction, according to a post on the companys Security Vulnerability Research and Defense (SVRD) blog . When the processor executes a div ...
Microsoft denies the severity of a Media Player exploit
Betanews —
... . "After that report, other organizations picked the report up and claimed that the issue was a code execution vulnerability in Windows Media Player. Those claims are false. We've found no possibility for code execution in this issue. Yes, the proof of concept code does trigger a crash of Windows Media player, but the application can be restarted right away and doesn't affect the rest of the system." As the new Microsoft vulnerability team's Jonathan Ness blogged in a separate post , the crash takes place when an intentionally malformed WAV file produces data that would ...

