Feeds

Win Media Player hole surrenders your machine

Joo own3d, porn lover

  • alert
  • submit to reddit

Top three mobile application threats

The Windows Media Player ASX (Active Stream Redirector) processor contains an unchecked buffer susceptible to an overrun which could enable an attacker to run arbitrary code on a machine with the victim's level of permission, a Microsoft security bulletin warns.

Media Player 6.4 and 7.0 are affected; and earlier, currently-unsupported versions 'may or may not be,' the company says.

Developing an exploit would require the cobbling together of a malicious file which could be circulated via e-mail or linked on a malicious Web site. All that remains is to entice the unlucky victim to open it. Naming it sororitysuck.asx ought to do the trick here, we reckon.

Alternatively, a malicious HTML page could be set up to run an attack script automatically when it's viewed.

A second, less destructive, vulnerability could enable an attacker to exploit maliciously-crafted shortcuts, which Media Player 6.4 and 7.0 save to the user's temporary files directory with a known file name.

"It's possible for HTML code to be stored in such a shortcut and launched via a Web page or HTML e-mail, in which case the code would run in the Local Computer Zone rather than the Internet Zone. An attacker could exploit this vulnerability to read - but not add, delete or modify - files on another user's computer," the security bulletin explains.

Media Player 6.4 users can download a patch to clear up both defects here; while 7.0 users can fix their systems by upgrading to 7.1 here. ®

Top three mobile application threats

More from The Register

next story
Dropbox defends fantastically badly timed Condoleezza Rice appointment
'Nothing is going to change with Dr. Rice's appointment,' file sharer promises
Audio fans, prepare yourself for the Second Coming ... of Blu-ray
High Fidelity Pure Audio – is this what your ears have been waiting for?
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Did a date calculation bug just cost hard-up Co-op Bank £110m?
And just when Brit banking org needs £400m to stay afloat
Sorry London, Europe's top tech city is Munich
New 'Atlas of ICT Activity' finds innovation isn't happening at Silicon Roundabout
Zucker punched: Google gobbles Facebook-wooed Titan Aerospace
Up, up and away in my beautiful balloon flying broadband-bot
Apple DOMINATES the Valley, rakes in more profit than Google, HP, Intel, Cisco COMBINED
Cook & Co. also pay more taxes than those four worthies PLUS eBay and Oracle
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.