HTTP: Microsoft DirectShow Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Microsoft DirectShow. A successful attack can allow attackers to execute remote code in the context of the current logged in user.

Extended Description

Microsoft DirectX is prone to a remote code-execution vulnerability because the DirectShow component fails to properly handle QuickTime media files. Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application that uses DirectX. Failed exploit attempts will result in a denial-of-service condition.

Affected Products

Nortel_networks self-service_media_processing_server,Nortel_networks contact_center-cct

References

BugTraq: 35139

CVE: CVE-2009-1537

Short Name
HTTP:STC:DL:DS-ATOM-TABLE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2009-1537 Code DirectShow Execution Microsoft Remote bid:35139
Release Date
05/29/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3720
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

CVSS Score

9.3

Found a potential security threat?