• caglararli@hotmail.com
  • 05386281520

Windows Media Player crash not exploitable for code execution

Çağlar Arlı      -    13 Views

Windows Media Player crash not exploitable for code execution

On Christmas Day, the MSRC opened a case tracking a Bugtraq-posted POC describing a “malformed WAV,SND,MID file which can lead to a remote integer overflow”. By Saturday evening, we saw reputable internet sources claiming this bug could lead to executing arbitrary code on the system. We investigated right away and found that this bug cannot be leveraged for arbitrary code execution.