MS.Media.Player.DirectoryTraversal
Description
This indicates an attempt to execute potentially malicious code via Microsoft Windows Media Player.
Due to inadequate input sanitization in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP, remote attackers may be able to execute arbitrary code on a target system by passing a skins file with a specially crafted URL to the vulnerable application.
Affected Products
Microsoft Windows Media Player XP
Microsoft Windows Media Player 7.1
Impact
Attackers can execute arbitrary code remotely on the victim system.
Recommended Actions
Apply the appropriate patches from Microsoft and/or upgrade the program to the latest non-vulnerable version.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2019-11-22 | 15.729 | Name:MS. MediaPlayer. DirectoryTraversal:MS. Media. Player. DirectoryTraversal |