All the latest UK technology news, reviews and analysis

Experts warn of Media Player vulnerability

by Shaun Nichols

More from this author

11 Dec 2006

Be the first to comment

  • Tweet this
Microsoft
Microsoft is investigating reports of a Media Player flaw

A newly discovered security vulnerability in Windows Media Player has prompted security firms to warn users to remain extra vigilant and alter the way they handle a certain type of file.

According to a Microsoft security advisory, an attacker could use a specially crafted Media Player .asx file to gain control of a user's system and remotely execute malware. 

The file could be placed in an HTML file, causing it to be automatically launched by the user's web browser.

Microsoft has confirmed the vulnerability and said that it is investigating the issue.

Secunia has given the vulnerability a rating of 'highly critical', the security firm's second highest alert level. 

Originally disclosed on 22 November, and thought to cause only a denial-of-service attack, security research firm eEye now believes that exploit code could be written for the vulnerability. 

EEye suggests that users can mitigate the threat by changing the default application to load .asx files. 

WatchGuard security analyst Corey Nachreiner, however, believes that users should not panic over the vulnerability. 

In a posting to WatchGuard's newswire feed entitled 'Unpatched Windows Media Player vulnerability announced; world fails to end,' Nachreiner downplays the immediate urgency of the flaw.

"While I do not doubt eEye's findings, there is a big difference between a flaw assumed to allow code execution and one confirmed to allow code execution, " he said.

Nachreiner pointed out that the Media Player vulnerability does not pose as serious a threat to users as the currently unpatched and active Word exploit.

The analyst still recommends users to follow eEye's steps to mitigate the effect of the vulnerability.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Order Processing Specialist

Order Processing Specialist - 12 Month Fixed Term Contract...

Inside Sales Manager - Berkshire - Global Software Co!

Great opening with one of the worlds leading information...

JAVA J2EE Developer required with RIA, web services, REST, JSON, AJAX

JAVA J2EE Developer required with RIA, web services...

Linux Administrator

Hi, Job Title : Linux Admin Location : Brussels...

To send to more than one email address, simply separate each address with a comma.