Lucene search

K
cve[email protected]CVE-2009-2525
HistoryOct 14, 2009 - 10:30 a.m.

CVE-2009-2525

2009-10-1410:30:01
CWE-94
web.nvd.nist.gov
30
cve-2009-2525
windows
media runtime
remote code execution
crafted media files
streaming content

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.759 High

EPSS

Percentile

98.2%

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2) crafted streaming content, aka โ€œWindows Media Runtime Heap Corruption Vulnerability.โ€

Affected configurations

NVD
Node
microsoftwindows_2000sp4
AND
microsoftwindows_media_format_runtimeMatch9.0
OR
microsoftwindows_media_playerMatch9
Node
microsoftwindows_media_format_runtimeMatch9.0
OR
microsoftwindows_media_format_runtimeMatch9.5
OR
microsoftwindows_media_format_runtimeMatch11
AND
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2x64
OR
microsoftwindows_xpsp3
Node
microsoftwindows_media_format_runtimeMatch9.5
AND
microsoftwindows_server_2003sp2
Node
microsoftwindows_media_format_runtimeMatch11
AND
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_server_2008sp2x32
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_vista
OR
microsoftwindows_vistax64
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.759 High

EPSS

Percentile

98.2%