First published: Wed Jul 10 2013(Updated: )
The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime 11 and Windows Media Player 11 and 12 allows remote attackers to execute arbitrary code via a crafted media file, aka "WMV Video Decoder Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Media Format Runtime | =9 | |
Microsoft Windows Media Format Runtime | =9.5 | |
Microsoft Windows Media Format Runtime | =11 | |
Microsoft Windows Media Player | =11 | |
Microsoft Windows Media Player | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3127 is rated as critical due to its potential for remote code execution.
To fix CVE-2013-3127, users should apply the security updates provided by Microsoft for affected versions of Windows Media Format Runtime and Windows Media Player.
CVE-2013-3127 affects Microsoft Windows Media Format Runtime versions 9, 9.5, 11 and Microsoft Windows Media Player versions 11 and 12.
Yes, CVE-2013-3127 can be exploited by sending a crafted media file to the affected system.
Not addressing CVE-2013-3127 exposes systems to the risk of remote code execution, allowing attackers to potentially take control of the affected systems.