Submit a Story!
Windows Media Player crash not exploitable for code execution
On Christmas Day, the MSRC opened a case tracking a Bugtraq-posted POC describing a “malformed WAV,SND,MID file which can lead to a remote integer overflow”. By Saturday evening, we saw reputable internet sources claiming this bug could lead to executing arbitrary code on the system. We ...
Comments
Blog Reactions

Microsoft Disputes Claim of Windows Media Player Vulnerability
eWeek - RSS Feeds — ... the SANS Internet Storm Center Web site over the weekend stated a reader had tested proof-of-concept (POC) code on a fully patched Windows XP Service Pack 3 system and caused Windows Media Player 9 and 11 to crash. However, while Microsoft officials conceded the proof-of-concept code could trigger a crash, they found no possibility of arbitrary code execution. “This particular crash is an unhandled CPU exception when executing a div instruction,” according to a post on the company’s Security Vulnerability Research and Defense (SVRD) blog . “When the processor executes a “div ...

Microsoft denies the severity of a Media Player exploit
Betanews — ... . "After that report, other organizations picked the report up and claimed that the issue was a code execution vulnerability in Windows Media Player. Those claims are false. We've found no possibility for code execution in this issue. Yes, the proof of concept code does trigger a crash of Windows Media player, but the application can be restarted right away and doesn't affect the rest of the system." As the new Microsoft vulnerability team's Jonathan Ness blogged in a separate post , the crash takes place when an intentionally malformed WAV file produces data that would ...

Related Content
An update is available for Windows Media Center and Windows Media Player in Windows 7 Beta
support.microsoft.com 1/9/2009 — An update is available for Windows Media Center and Windows Media Player in Windows 7 Beta. This update addresses some issues with Windows Media Center playback, recording, and MP3 file support in Windows. Playback and recording issues that are fixed ...
Questions about Vulnerability Claim in Windows Media Player
blogs.technet.com 12/29/2008 — Happy holidays to everyone. While it’s been a snowy holiday season for us in the Pacific Northwest (some of us are still snowed in), the MSRC never closes and we are always working to help keep customers safe. In that vein, we’ve received some ...
SecurityTracker.com Archives - Windows Media Player Integer Overflow in Playing WAV Files Lets Remote Users Deny Service
securitytracker.com 12/29/2008 — Description: A vulnerability was reported in Windows Media Player. A remote user can cause the target user's player to crash. A remote user can create a specially crafted WAV, SND, or MIDI file that, when loaded by the target user, will cause the ...
Updated: Yule Log Visualization for Windows Media Player 11/Vista/XP
blog.seanalexander.com 12/25/2008 — Last week, I got two emails from readers asking if there was a way to get the old Yule Log Visualization for Windows Media Player running in Vista. Originally released as a part of the Windows Media Bonus Pack for Windows XP , ...
Microsoft downplays Windows Media Player bugLatest from Computerworld 12/29/2008
Microsoft Corp. today dismissed reports of a critical vulnerability in its Windows Media Player, saying that the researcher who claims the bug could be exploited is wrong.
Microsoft denies vulnerability in Windows Media PlayerCNET News.com 12/30/2008
Software giant says flaw is a "reliability issue with no security risk to customers" and criticizes researcher for not contacting the company.
Windows Media Player flaw deniedThe Register 12/30/2008
Security pantomime Researchers reckon a security bug in Windows Media Player creates a means for hackers to inject hostile code onto vulnerable systems. However Microsoft has denied this, saying that the bug only creates a means to crash the ...