First published: Wed Dec 10 2008(Updated: )
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Microsoft Windows Media Player | =6.4 | |
Any of | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Microsoft Windows Media Format Runtime | =7.1 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
Microsoft Windows Media Services | =4.1 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
Microsoft Windows Media Services | =9 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Microsoft Windows Media Services | =2008 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
All of | ||
Microsoft Windows Media Format Runtime | =11 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =gold | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Microsoft Windows Media Format Runtime | =11 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
All of | ||
Microsoft Windows Media Format Runtime | =9.5 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
All of | ||
Microsoft Windows Media Format Runtime | =9.5 | |
Any of | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Microsoft Windows Media Format Runtime | =9 | |
Any of | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Media Player | =6.4 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Media Format Runtime | =7.1 | |
Microsoft Windows Media Services | =4.1 | |
Microsoft Windows Media Services | =9 | |
Microsoft Windows Media Services | =2008 | |
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Media Format Runtime | =11 | |
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =gold | |
Microsoft Windows XP | ||
Microsoft Windows Media Format Runtime | =11 | |
Microsoft Windows Media Format Runtime | =9.5 | |
Microsoft Windows Media Format Runtime | =9.5 | |
Microsoft Windows Media Format Runtime | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3009 has a critical severity rating as it allows remote code execution due to improper validation of Service Principal Name (SPN) identifiers.
To fix CVE-2008-3009, users should update Microsoft Windows Media Player, Windows Media Format Runtime, or Windows Media Services to the latest patched version.
CVE-2008-3009 affects Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008.
Yes, CVE-2008-3009 can be exploited remotely by attackers sending crafted authentication requests to vulnerable services.
CVE-2008-3009 can enable attackers to execute arbitrary code on vulnerable systems, which may lead to complete system compromise.