The Register®

Biting the hand that feeds IT

MS Media Player gives up your box

Don't worry, they fixed it before you were rooted

If there's one thing that occasionally tempts me to miss Windows, it's the mediocre multimedia support in Linux. But then again, my media player doesn't allow remote attackers to own my box. It's a trade-off, I'll allow.

Yesterday MS 'fessed up to three new holes in WMP, the most serious of which allows remote evildoers to run arbitrary code on your priceless Windoze machine.

However, and we'll quote Redmond directly, the remaining two are hardly benign. We have:

"A privilege-elevation vulnerability that could enable an attacker who can physically logon locally to a Windows 2000 machine and run a program to obtain the same rights as the operating system."

And "a script-execution vulnerability related that could run a script of an attacker's choice as if the user had chosen to run it after playing a specially formed media file and then viewing a specially constructed Web page. This particular vulnerability has specific timing requirements that makes attempts to exploit vulnerability difficult and is rated as low severity."

"Specific timing requirements" in this case means that unless you do precisely what you're told by your pal in MSM, you won't get nailed. You have to play a file, close WMP and then hit a malicious Web site. Naturally, you'd never do that.

There's a cumulative patch posted here, with additional details.

Free Report - "High-level Best Practices in Software Configuration Management: How to deploy SCM software to the maximum advantage"

Don’t Miss

Warning: roadworksNetbooks and Mini-Laptops

Buyer's Guide They're little and we love 'em. But which ones are best?

Warning: roadworksIntel shakes AMD's chip-fabbing baby

Cross-licensing custody battle

Emails show journalist rigged Wikipedia's naked shorts

Overstock's Byrne vindicated amidst economic meltdown

Warning StopYours truly, angry mob

Book extract Bringing Nothing To The Party: Cleaning up the net, one satirical vigilante page at a time