MS06-005 Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)

MS06-005
Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)
http://www.microsoft.com/technet/security/bulletin/MS06-005.mspx

Microsoft Severity Rating: Critical

Description
eEye Digital Security discovered this critical vulnerability in Windows Media Player. The vulnerability allows a remote attacker to reliably overwrite heap memory with user-controlled data and execute arbitrary code in the context of the user who executed the player.

Windows Media Player has a security issue within Media Player versions 7.1 through 10 on all Windows OS's. This flaw is a heap overflow, which would allow an attacker to use multiple vectors to exploit it. Attackers may create .asx files and open them with a URL, use Activex embeded in an HTML page, or create a Media Player skin file.

Recommendations
There are no known reports of this flaw being used by attackers or any other malicious individuals. eEye recommends that you install this patch in a timely manner to prevent the potential future use of this vulnerability.

Protect Your Assets
Stay Secure with ZoneLabs ZoneAlarm Internet Security Suite

Submitted by cybernoggin on Thu, 02/16/2006 - 8:05am. categories [ | ] cybernoggin's blog | login or register to post comments
Submitted by Anonymous (not verified) on Thu, 04/13/2006 - 5:27am.

********************************************************************
Title: Microsoft Security Bulletin Re-Releases Issued: April 11, 2006 ********************************************************************

Summary
=======
The following bulletins have undergone a major revision increment. Please see the appropriate bulletin for more details. * MS06-005

Bulletin Information:
=====================
* MS06-005

- http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx
- Reason for Revision: Microsoft updated this bulletin today to advise customers that revised versions of the security update are available for Microsoft Windows Media Player 10 when installed on Windows XP Service Pack 1 or Windows XP Service Pack 2, listed in the "Affected Components" section. For more information, see on "What are the known issues that customers may experience when they install this security update?"

We revised this update to report an issue when a user tries to seek, fast rewind, or fast forward when using Windows Media Player 10

- Originally posted: February 14, 2006
- Updated: April 11, 2006
- Bulletin Severity Rating: Critical
- Version: 2.0

********************************************************************