Threat Encyclopedia

MS.Media.Player.DirectoryTraversal

description-logoDescription

This indicates an attempt to execute potentially malicious code via Microsoft Windows Media Player.
Due to inadequate input sanitization in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP, remote attackers may be able to execute arbitrary code on a target system by passing a skins file with a specially crafted URL to the vulnerable application.

affected-products-logoAffected Products

Microsoft Windows Media Player XP
Microsoft Windows Media Player 7.1

Impact

Attackers can execute arbitrary code remotely on the victim system.

recomended-action-logoRecommended Actions

Apply the appropriate patches from Microsoft and/or upgrade the program to the latest non-vulnerable version.

CVE References

CVE-2003-0228