HTTP: Microsoft Media Player Malformed Media File

This signature detects attempts to exploit a known flaw in Microsoft Media Player. The vulnerability could allow remote code execution if a user opens a specially crafted media file that is hosted on a website or sent as an email attachment. An attacker who successfully exploited the vulnerability could gain the same user rights as the local user.

Extended Description

Microsoft Windows is prone to a remote buffer-overflow vulnerability when handling a specially crafted media file. An attacker can exploit this issue by enticing an unsuspecting user to view a webpage containing malicious content or to open a malicious media file. Successful exploits will allow the attacker to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.

Affected Products

Microsoft windows_server_2008_for_itanium-based_systems

References

BugTraq: 51913

CVE: CVE-2012-0150

Short Name
HTTP:STC:STREAM:MAL-MEDIA
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2012-0150 File Malformed Media Microsoft Player bid:51913
Release Date
02/13/2012
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?