MS03-021: Windows Media Player Library Access (819639)

high Nessus Plugin ID 11774

Synopsis

Arbitrary code can be executed on the remote host through the media player.

Description

An ActiveX control included with Windows Media Player 9 Series may allow a rogue website to gain information about the remote host.

An attacker could exploit this flaw to execute arbitrary code on this host with the privileges of the user running Windows Media Player.

To exploit this flaw, an attacker would need to set up a rogue website and lure a user of this host into visiting it.

Solution

Microsoft has released a set of patches for WMP 6.4, 7.1 and XP.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2003/ms03-021

Plugin Details

Severity: High

ID: 11774

File Name: smb_nt_ms03-021.nasl

Version: 1.45

Type: local

Agent: windows

Published: 6/26/2003

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:windows_media_player

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Excluded KB Items: SMB/Win2003/ServicePack

Exploit Ease: No known exploits are available

Patch Publication Date: 6/25/2003

Vulnerability Publication Date: 6/25/2003

Reference Information

CVE: CVE-2003-0348

BID: 8034

CERT: 320516

MSFT: MS03-021

MSKB: 819639