Home / bulletins

MS06-078: Vulnerability in Windows Media Format Could Allow Remote Code Execution (923689) - Version:6.1

Posted on 25 November 2008

Severity Rating: Critical - Revision Note: V6.1 (November 25, 2008): Bulletin updated to correct the filename, Wwmvcore.dll, to Wmvcore.dll for file information for Windows Media Format 9.5 Series Runtime on Windows XP Professional x64 Edition and Windows Server 2003 x64 Edition.Summary: This update resolves two newly discovered vulnerabilities. These vulnerabilities are documented in the Vulnerability Details section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Link

Other versions

 

TOP