>> Microsoft Windows Media Player Remote Command Execution Vulnerabilities (MS06-078)
Title : Microsoft Windows Media Player Remote Command Execution Vulnerabilities (MS06-078) VUPEN ID : VUPEN/ADV-2006-4882 CVE ID : CVE-2006-4702 - CVE-2006-6134
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-07
Technical Description
Two vulnerabilities have been identified in Microsoft Windows Media Player, which could be exploited by remote attackers to compromise a vulnerable system or cause a denial of service. These flaws are due to buffer overflow errors when processing malformed ASX or ASF files, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into visiting a specially crafted web page.