Windows Media Player Flaw Puts PCs at Risk
Security hole in media player's antipiracy feature could allow hackers to access your computer.
Joris Evers, IDG News Service
A flaw in an antipiracy feature in Microsoft's Windows Media Player could put systems at risk to hacker attacks, Microsoft warned in a security bulletin Wednesday.
All the currently supported versions of Windows Media Player, versions 6.4, 7.1, and Windows Media Player for Windows XP, are flawed in the way they handle a license request for certain secure media files. An attacker could exploit this flaw to hijack a user's system and take any action a user is capable of, Microsoft says.
The media player, when it requests license information from a server, erroneously discloses the location on the user's system of the Internet Explorer cache, which is used by IE to temporarily store files. An attacker could use this information to bypass IE's security mechanisms and run executable files in the cache, Microsoft says.
IE's Information
IE places information that a Web page or an HTML e-mail need to have stored on the user's system--a file for example--in the cache and retrieves it later for handling. One way the cache is protected against direct access is by using dynamic folder names. The cache should only be accessible by IE, Microsoft says.
An attacker could exploit the vulnerability by sending an HTML e-mail with a specially formed Windows Media file or by hosting the file on a Web site. In both cases, the IE cache location could be returned to the attacker's site once the file is played, at which point the attacker could try to run an executable in the cache, Microsoft says.
Microsoft released a software patch to fix this problem. The patch, called a cumulative patch, also includes all previously released patches for Windows Media Player and two other new patches that fix less broad security problems.
Critical Fix
Microsoft does rate a newly patched privilege elevation vulnerability in Windows Media Player 7.1 when run on Windows 2000 "critical." A malicious user could exploit the flaw in a part of Media Player that deals with storage devices to increase his privilege level on a Windows 2000 system. The user would need to write a special software program to do that, Microsoft says.
The third newly patched vulnerability could allow an attacker to run a script of his choice on the user's computer and affects only Windows Media Player 7.1. Microsoft deems this a "low" risk vulnerability as a successful attack requires a specific series of user actions to follow in exact order.
More information about the flaws and the patch, which Microsoft urges users apply immediately, can be found on Microsoft's Web site.
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Laptop Showcase
SMB Networking Center
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2009 - 1 User/3 PCPrice: $34.99
Norton Internet Security 2009 - 1 User/1 PCPrice: $15.95
Norton 360Price: $25.00
Internet Security 2009Price: $15.99
Norton Internet Security 2009 - 1 User/3 PC, Small BoxPrice: $20.50
Internet Security 2009Price: $24.95
- Cisco Small Business Center Find out how to keep employees mobile, connected and productive with secure wireless networking.
- Dell Servers for Small Business Click here to see how a Dell server can help you back up your company's data and save you valuable time.




