This application requires Javascript for optimal performance.

MS.Media.Player.Code.Execution

Release Date

Aug 20, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a remote code-execution vulnerability in Microsoft Windows Media Player 11, which was caused by improper operation on a file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server.

Affected Products

Nortel Networks ENSM- Enterprise NMS 0
Nortel Networks ENSM - Enterprise NMS 10.5
Nortel Networks ENSM - Enterprise NMS 10.4
Microsoft Windows Media Player 11
HP Storage Management Appliance III
HP Storage Management Appliance II
HP Storage Management Appliance I
HP Storage Management Appliance 2.1

Recommended Actions

Please refer to Microsoft advisory for patches or updates:
http://www.microsoft.com/technet/security/Bulletin/ms08-054.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-2253

Reference/s

http://www.microsoft.com/technet/security/Bulletin/ms08-054.mspx (MS-ID)
http://www.securityfocus.com/bid/30550 (BugTraq)

Reference: VID-15820