CVE-2013-4858: Input Validation
Published Dec 30, 2013
·Updated
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.
Affected Software
2 affected components
Microsoft Windows Movie Maker=2.1.4026.0
Microsoft Windows XP=sp3
Event History
Dec 30, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4858?
CVE-2013-4858 has a severity rating that indicates it could lead to a denial of service due to application crashes.
2
How do I fix CVE-2013-4858?
To mitigate CVE-2013-4858, it's recommended to update or uninstall Microsoft Windows Movie Maker and avoid opening potentially malicious .wav files.
3
Who is affected by CVE-2013-4858?
CVE-2013-4858 affects users running Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3.
4
Can CVE-2013-4858 be exploited remotely?
Yes, CVE-2013-4858 can be exploited remotely through specially crafted .wav files.
5
What are the symptoms of exploitation of CVE-2013-4858?
Exploitation of CVE-2013-4858 typically results in the crashing of the Windows Movie Maker application.