Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Windows media decompression vulnerability could allow remote code execution


Report ID: MS201302003
Date Published: 22 February 2013

Criticality: Critical
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008




Summary

A vulnerability that exists when handling media content could be exploited to allow an attacker to execute code on an affected system.



Detailed Description

Microsoft has issued a security update following a report on a vulnerability that exists when handling media content. The vulnerability was caused by Microsoft DirectShow's failure to properly handle specially crafted media content, and can be exploited into allowing an attacker to execute code on an affected system.

The vulnerability has been fixed in the update by correcting the way in handling media content. Users are recommended to install this update to protect their system from possible exploit attempts.



CVE Reference

CVE-2013-0077



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-011)




Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.