>> Microsoft DirectX File Handling Code Execution Vulnerabilities (MS07-064)
Title : Microsoft DirectX File Handling Code Execution Vulnerabilities (MS07-064) VUPEN ID : VUPEN/ADV-2007-4180 CVE ID : CVE-2007-3895 - CVE-2007-3901
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-11
Technical Description
Multiple vulnerabilities have been identified in Microsoft DirectX, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by an input validation error in DirectShow when processing Synchronized Accessible Media Interchange (SAMI) file parameters, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted file or visiting a malicious web page.
The second vulnerability is caused by an input validation error in DirectShow when parsing WAV and AVI file parameters, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted file or visiting a malicious web page.