Main > Security & Privacy > Encrypting >

Windows Media Player XP Cumulative Vulnerability Patch MS02-032



 

Windows Media Player XP Cumulative Vulnerability Patch MS02-032

Sponsored Links

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 10 (1 times)
File size: 1.3MB
Platform: Windows XP
License: Freeware
Price:
Downloads: 29
Date added: 2002-06-29
Publisher: Microsoft. Corp.

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 description

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 is a powerful software which includes the functionality of all previously released patches for Windows Media Player XP.

In addition, it eliminates the following three newly discovered vulnerabilities: An information disclosure vulnerability that could allow an attacker to run code on the user's system and is rated as critical severity.

A privilege elevation vulnerability that could enable an attacker who can physically log on locally to a Windows 2000 machine and run a program to obtain the same rights as the operating system.

A script execution vulnerability related that could run a script of an attacker's choice as if the user had chosen to run it after playing a specially formed media file and then viewing a specially constructed web page.

This particular vulnerability has specific timing requirements that make attempts to exploit vulnerability difficult and is rated as low severity.

This patch also introduces a configuration change relating to file extensions associated with Windows Media Player.

Finally, it introduces a new, optional, security configuration feature for users or organizations that want to take extra precautions beyond applying IE patch MS02-023 and want to disable scripting functionality in the Windows Media Player for versions 7.x or higher.

Major Features:

  1. Cache Path Disclosure via Windows Media Player:
    • Customers who have applied MS02-023 are protected against attempts to automatically exploit this issue through HTML email when they read email in the Restricted Sites zone. Outlook 98 and Outlook 2000 with the Outlook Email Security Update, Outlook 2002 and Outlook Express 6.0 all read email in the Restricted Sites zone by default.
    • The vulnerability does not affect media files opened from the local machine. As a result of this, users who download and save files locally are not affected by attempts to exploit this vulnerability.
  2. Privilege Elevation through Windows Media Device Manager Service:
    • This issue affects only Windows Media Player 7.1. It does not affect Windows Media Player for Windows XP nor Windows Media Player 6.4.
    • The vulnerability only affects Windows Media Player 7.1 when run on Windows 2000. It does not impact systems that have no user security model such as Windows 98 or Windows ME systems.
    • This issue only affects console sessions; users who logon via terminal sessions cannot exploit this vulnerability.
    • An attacker must be able to load and run a program on the system. Anything that prevents an attacker from loading or running a program could protect against attempts to exploit this vulnerability.
  3. Media Playback Script Invocation:
    • A successful attack requires a specific series of actions follows in exact order, otherwise the attack will fail. Specifically:
    • A user must play a specially formed media file from an attacker.
    • After playing the file, the user must shut down Windows Media Player without playing another file.
    • The user must then view a web page constructed by the attacker.

WareSeeker Editor

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 Screenshot

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 Keywords

Bookmark Windows Media Player XP Cumulative Vulnerability Patch MS02-032

Hyperlink code:
Link for forum:

Windows Media Player XP Cumulative Vulnerability Patch MS02-032 Copyright

WareSeeker.com do not provide cracks, serial numbers etc for Windows Media Player XP Cumulative Vulnerability Patch MS02-032. Any sharing links from rapidshare.com, yousendit.com or megaupload.com are also prohibited.

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Prevent malicious users from exploiting security vulnerabilities in Windows Media Player 6.4. Free Download
Windows Media Player 7 Skins File Download Vulnerability Patch is known as a patch removing a security vulnerability in Microsoft Windows Media Player 7 Free Download
Patch two security vulnerabilities in Windows Media Player. Free Download
Dress up your Player for the holidays, organize your holiday music, or reorganize your whole music library Free Download
Windows Media Player 11 Integrator is a very small utility that enable you to easily integrate WMP11 into a windows source Free Download
Windows Media Player 9 Series Free Download
The latest Windows Media codecs. Free Download
Patch Available for OCX Attachment Vulnerability Free Download