>> Windows Media Encoder Code Execution Vulnerability (MS08-053)
Title : Windows Media Encoder Code Execution Vulnerability (MS08-053) VUPEN ID : VUPEN/ADV-2008-2521 CVE ID : CVE-2008-3008 CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-09
A vulnerability has been identified in Microsoft Windows Media Encoder, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a buffer overflow error in the "wmex.dll" ActiveX control when processing malformed data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a malicious web page.
Credits Vulnerability reported by Nguyen Minh Duc, Le Manh Tung, and Bach Khoa Internetwork Security Center (BKIS) Hanoi University of Technology (Vietnam).