First published: Sat Dec 18 2004(Updated: )
The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Windows Media Player | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1325 is considered to be a moderate severity vulnerability, as it can lead to information disclosure.
To mitigate CVE-2004-1325, users should upgrade to a newer version of Windows Media Player that is not affected by this vulnerability.
CVE-2004-1325 can be exploited by attackers to check for the existence of files on the local system, which can lead to further attacks.
CVE-2004-1325 affects users of Microsoft Windows Media Player version 9.
CVE-2004-1325 allows an attacker to determine the existence of files on the victim's local system.