Multiple vulnerabilities have been identified in Microsoft Windows, which could be exploited by attackers to compromise a vulnerable system.
The first issue is caused by a memory corruption error in the AVIFile API (Avifil32.dll) when processing AVI files with malformed headers, which could be exploited to crash an affected application or execute arbitrary code e.g. via a malicious web page.
The second vulnerability is caused by an integer overflow error in the AVIFile API (Avifil32.dll) when processing data within AVI files, which could be exploited to crash an affected application or execute arbitrary code e.g. via a malicious web page.