• On BNET: 3 worst things about the iPhone 3G S

October 18, 2005 7:23 AM PDT

Security flaw touches Windows Media Player, IE

  • Post a comment
A "critical" flaw that affects both Microsoft's Windows Media Player and Internet Explorer has been uncovered, a security company reported late Monday.

The security flaw, which is found in the default installations of Media Player and the IE browser, could let attackers launch a remote execution of code, according to an advisory posted by eEye Digital Security.

Systems affected by the flaw include Windows XP with Service Pack 1 and Service Pack 2, Windows NT, Windows 2003 and Windows 2003 SP1, and all versions of Windows 2000.

Although eEye does not believe the vulnerability is "wormable," the company rated it "critical" because it could allow for a remote execution of code and affects installations of Media Player and IE at their default settings, an eEye representative said.

"The flaw can be exploited if the user opens a wrong file or goes to a wrong Web site," said Marc Maiffret, eEye's chief hacking officer. "Then the attacker can execute code as the user, who is viewing the file or Web site."

A Microsoft spokeswoman confirmed the software giant had received eEye's advisory, but noted that because details of the vulnerabilities were not made public, there haven't been any known attempts to exploit the flaws.

The Microsoft Security Response Center continues to investigate the report, the spokeswoman said.

The discovery of this latest flaw comes days after Microsoft issued an advisory that a security patch it released early last week contained problems that could, in some instances, lock people out of their PC. As part of its regular monthly patching schedule, Microsoft last week issued patches for 14 security flaws in Windows, one of which had the potential to be exploited by a major worm.

eEye noted that the latest vulnerability is not linked to any of the 14 security flaws patched last week.

See more CNET content tagged:
eEye Digital Security, security flaw, flaw, advisory, Microsoft Windows Media Player

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (-0.22%) -0.05 22.39
Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right