Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:DL:WMP-SKIN-DECOMP

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft Windows Media Player Skin Decompression Code Execution

Release Date

2010/10/14

Update Number

1792

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Microsoft Windows Media Player Skin Decompression Code Execution


This signature detects attempts to exploit a known code execution vulnerability in Microsoft Windows Media Player. It is caused due to a boundary error when decompressing the encoded data from WMZ and WMD files. A remote attacker can exploit this by enticing the target user to open crafted WMZ and WMD files, potentially causing arbitrary code to be injected and executed in the security context of the currently logged in user. In a simple attack case, the affected Windows Media Player can terminate when the malicious page is opened. In a sophisticated attack, where the malicious user is successful in injecting and executing supplied code, the behavior of the system is dependent on the nature of the injected code. Any code injected into the vulnerable component can execute in the security context of the currently logged in user.

Extended Description

Microsoft Windows Media Player is prone to a remote code-execution vulnerability when handling specially crafted compressed skin files. Attackers exploit this issue by coercing unsuspecting users to download and open Windows Media Player skin files (WMZ or WMD files). Successful exploits allow attackers to execute arbitrary code in the context of the vulnerable application. This facilitates the remote compromise of affected computers.

Affected Products

  • Avaya customer_interaction_express_(cie)_server 1.0
  • Avaya customer_interaction_express_(cie)_user_interface 1.0
  • Avaya customer_interaction_express_(cie)_user_interface 1.0.2
  • Microsoft windows_media_player 10.0
  • Microsoft windows_media_player 11
  • Microsoft windows_media_player 7.1
  • Microsoft windows_media_player 9.0

References

  • BugTraq: 25307
  • CVE: CVE-2007-3035

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out