On GameFAQs: The top 100 most popular games!
BNET Business Network:
BNET
TechRepublic
ZDNet

September 15th, 2008

Exploit published for Windows Media Encoder flaw

Posted by Ryan Naraine @ 9:59 am

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Malware, Microsoft, Passwords, Patch Watch, Pen testing, Viruses and Worms, Vulnerability research, Web 2.0, Windows Vista

Tags: Windows Media, Vulnerability, Microsoft Corp., Flaw, Microsoft Windows, Operating Systems, Security, Software, Ryan Naraine

Exploit published for Windows Media Encoder flawIf you haven’t applied Microsoft’s MS08-053 security update, now might be a good time to hit that patch button.

Proof-of-concept exploit code for the vulnerability, which allows remote code execution attacks via the Web, has been posted online, raising the likelihood that we’ll soon see in-the-wild exploitation.

The exploit, available at Milw0rm.com,   targets a critical flaw in the WMEX.DLL ActiveX control installed by the Windows Media Encoder 9 Series.  This ActiveX control is marked as Safe for Scripting and can be exploited view the Internet Explorer browser.

[ SEE: MS Patch Tuesday: 8 critical security holes patched ]

From Microsoft’s bulletin:

  • The vulnerability could allow remote code execution if a user views a specially crafted Web page. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

The bulletin is rated “critical” on supported/affected editions of Microsoft Windows 2000, Windows XP and Windows Vista.   On Windows Server 2003 and Windows Server 2008, it carries a “moderate” severity rating.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
Then I slighly retract some of my comment.
What is the penetration of Encoder? Is it something that everyone downloads eventually or only for geeks. My point about an encoder flaw being accessible when surfing the web through activeX control... (Read the rest)
Posted by: TripleII Posted on: 09/15/08 You are currently: a Guest | | Terms of Use
Sigh, tight integration of all apps.  TripleII | 09/15/08
Worth noting that WM Encoder does not come with Windows  PB_z | 09/15/08
Then I slighly retract some of my comment.  TripleII | 09/15/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here