1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Windows Movie Maker Buffer Overflow Vulnerability

Report ID: SA201006421
Source: F-Secure
Date of Discovery: 09.03.2010
Criticality: Urgent
Affects:
Windows Movie Maker
Microsoft Producer 2003

Compromise From: From remote
Compromise Type: Remote code execution
System access

Summary

A remote code execution vulnerability in Windows Movie Maker and Microsoft Producer 2003 could allow an attacker to gain complete control of an affected system.

Detailed Description

Microsoft has reported a vulnerability in Windows Movie Maker and Microsoft Producer 2003, which is caused by the way these applications parse project file formats. A successful exploit could allow an attacker to remotely execute arbitrary code and gain access to the affected system through a specially crafted Movie Maker or Producer file.


4 May 2010: Micosoft has released an updated version of Producer 2003 and recommends that all users of the older version upgrade to the latest version. Users who do not wish to upgrade are advised to apply the workaround solution offered as a Microsoft FixIt.

Further information is available in the security bulletin:

 

Original Reference

CVE Reference

CVE-2010-0265