Vulnerability Name: | CVE-2006-4702 (CCN-30594) | ||||||||
Assigned: | 2006-12-12 | ||||||||
Published: | 2006-12-12 | ||||||||
Updated: | 2018-10-17 | ||||||||
Summary: | Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. If the end user has administrative rights, the attacker could take complete control of the affected system. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4702 Source: CCN Type: SECTRACK ID: 1017372 Windows Media Player and Windows Media Format Runtime ASF File Buffer Overflow Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1017372 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-274.htm Source: CCN Type: ASA-2006-274 MS06-078 Vulnerability in Windows Media Format Could Allow Remote Code Execution (923689) Source: CCN Type: Microsoft Security Bulletin MS06-078 Vulnerability in Windows Media Player Could Allow Remote Code Execution (923689) Source: CCN Type: Microsoft Security Bulletin MS07-068 Vulnerability in Windows Media File Format Could Allow Remote Code Execution (941569 and 944275) Source: HP Type: UNKNOWN SSRT061288 Source: BID Type: UNKNOWN 21505 Source: CCN Type: BID-21505 Windows Media Player Remote ASF File Buffer Overflow Vulnerability Source: CERT Type: US Government Resource TA06-346A Source: MS Type: UNKNOWN MS06-078 Source: XF Type: UNKNOWN win-media-asf-bo(30594) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:536 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |