Microsoft denies security risk in Windows Media

By Steven Musil, CNET News.com
Tuesday, December 30, 2008 11:44 AM

Microsoft on Monday denounced reports that a vulnerability exists in Windows Media Player that would allow for remote code execution.

Microsoft said in a company blog post that it had investigated reports that surfaced on the Internet last week and found them to be "false".

The flaw is "reliability issue with no security risk to customers," the company said on its Security Vulnerability Research & Defense blog.

The investigation followed claims published Wednesday on the Bugtraq security mailing list by researcher Laurent Gaffie that a vulnerability existed in Windows Media Player 9, 10, and 11.

Gaffie said the vulnerability would allow a hacker to create a malformed WAV, SND, or MIDI file to compromise a PC running Windows Vista or Windows XP, and included a proof-of-concept code he said would allow remote code execution.

Along with its denial, Microsoft also criticized Gaffie for publishing his claims without first contacting the software giant.

"The security researcher making the initial report didn't contact us or work with us directly but instead posted the report along with proof of concept code to a public mailing list. After that report, other organizations picked the report up and claimed that the issue was a code execution vulnerability in Windows Media Player. Those claims are false.

"We've found no possibility for code execution in this issue. Yes, the proof of concept code does trigger a crash of Windows Media player, but the application can be restarted right away and doesn't affect the rest of the system," Microsoft said.

The company said the flaw had already been identified during routine code maintenance and corrected in Windows Server 2003 Service Pack 2.

This article was first published as a blog post on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web