CVE-2008-3009: Critical severity windows media player vulnerability
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3009?
CVE-2008-3009 has a critical severity rating as it allows remote code execution due to improper validation of Service Principal Name (SPN) identifiers.
How do I fix CVE-2008-3009?
To fix CVE-2008-3009, users should update Microsoft Windows Media Player, Windows Media Format Runtime, or Windows Media Services to the latest patched version.
Which software versions are affected by CVE-2008-3009?
CVE-2008-3009 affects Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008.
Can CVE-2008-3009 be exploited remotely?
Yes, CVE-2008-3009 can be exploited remotely by attackers sending crafted authentication requests to vulnerable services.
What types of attacks can CVE-2008-3009 enable?
CVE-2008-3009 can enable attackers to execute arbitrary code on vulnerable systems, which may lead to complete system compromise.