Short Name |
HTTP:STC:IE:WMP-BMP-OF-1 |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Windows Media Player BMP Overflow (1) |
Release Date |
2006/04/11 |
Update Number |
1213 |
Supported Platforms |
idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects malformed BMP's opened by Windows Media Player. Versions 10 and prior are vulnerable. Attackers, who convince a user to open a malicious Web page or file, can cause a buffer overflow leading to arbitrary code execution with the user's privileges.
Microsoft Windows Media Player is prone to a remote buffer-overflow vulnerability. The vulnerability arises when the application handles a skin file containing a specially crafted bitmap image. This issue can also be triggered by just supplying a malicious bitmap to the application. Note, however, that Windows Media Player is not the default handler for bitmap files. A successful attack can corrupt process memory and result in arbitrary code execution. This may facilitate a remote compromise in the context of the vulnerable user.