CVE-2002-1844: High severity Microsoft Windows Media Player vulnerability
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the world-writable permission bits from the installed Windows Media Player 6.3 executables on Solaris so local users cannot modify or delete them. For example, as root run chmod o-w on each WMP 6.3 executable file (adjust paths to the actual installation locations).
Microsoft Windows Media Player 6.3 (Solaris) executables world-writable file permission = remove world-writable bit (e.g., chmod o-w on executables)
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1844?
CVE-2002-1844 has a medium severity rating due to the potential for privilege escalation by local users.
How do I fix CVE-2002-1844?
To fix CVE-2002-1844, change the permissions of the affected executables to remove world-writable access.
Which versions of Windows Media Player are affected by CVE-2002-1844?
CVE-2002-1844 specifically affects Microsoft Windows Media Player version 6.3 installed on Solaris.
Can CVE-2002-1844 be exploited remotely?
CVE-2002-1844 is not exploitable remotely; it requires local access to the affected system.
What systems are impacted by CVE-2002-1844?
CVE-2002-1844 impacts systems running Microsoft Windows Media Player 6.3 on the Solaris operating system.