HTTP: Microsoft Media Foundation CMP4MetadataHandler AddQTMetadata Use After Free

This signature detects attempts to exploit a known vulnerability against Windows Media Foundation. A successful attack can lead to arbitrary code execution.

Extended Description

A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'Microsoft Windows Media Foundation Remote Code Execution Vulnerability'.

Affected Products

Microsoft windows_10

References

CVE: CVE-2020-0939

Short Name
HTTP:STC:DL:MS-CMP4-MTADTA-UAF
Severity
Critical
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
AddQTMetadata After CMP4MetadataHandler CVE-2019-1430 CVE-2020-0939 Foundation Free Media Microsoft Use
Release Date
04/28/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

4.3

Found a potential security threat?