Lucene search

K
kasperskyKaspersky LabKLA10596
HistoryJun 09, 2015 - 12:00 a.m.

KLA10596 Code execution vulnerability in Windows Media Player

2015-06-0900:00:00
Kaspersky Lab
threats.kaspersky.com
28

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.131

Percentile

95.6%

An unspecified vulnerability was found in Windows Media Player. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed DataObject.

Original advisories

Microsoft bulletin

CVE-2015-1728

Related products

Microsoft-Windows-Media-Player

CVE list

CVE-2015-1728 critical

KB list

3033890

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Microsoft Windows Media Player versions from 10, 11 and 12

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.131

Percentile

95.6%