First published: Tue Aug 14 2007(Updated: )
Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka "Windows Media Player Code Execution Vulnerability Parsing Skins."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Media Player | =7.1 | |
Microsoft Windows Media Player | =10 | |
Microsoft Windows Media Player | =11 | |
Microsoft Windows Media Player | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3037 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-3037, update Microsoft Windows Media Player to the latest version provided by Microsoft.
CVE-2007-3037 affects Microsoft Windows Media Player versions 7.1, 9, 10, and 11.
CVE-2007-3037 enables remote attackers to execute arbitrary code on the victim's system.
Users can protect themselves from CVE-2007-3037 by avoiding the opening of suspicious WMZ or WMD skin files.