First published: Sun Dec 13 2009(Updated: )
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Windows Media Player |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4310 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2009-4310, it is recommended to apply the latest security updates provided by Microsoft for affected Windows versions.
CVE-2009-4310 affects Windows 2000 SP4, Windows XP SP2/SP3, and Windows Server 2003 SP2.
CVE-2009-4310 is a stack-based buffer overflow vulnerability in the Intel Indeo41 codec.
Yes, CVE-2009-4310 can be exploited remotely through maliciously crafted video files.