Vulnerability Name:

CVE-2008-5745 (CCN-47664)

Assigned:2008-12-24
Published:2008-12-24
Updated:2018-10-11
Summary:Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file.
Note: this has been incorrectly reported as a code-execution vulnerability.
Note: it is not clear whether this issue is related to CVE-2008-4927.
This bug cannot be leveraged for code execution according to the vendor.

Source 1 - http://blogs.technet.com/swi/archive/2008/12/29/windows-media-player-crash-not-exploitable-for-code-execution.aspx

Source 2 - http://blogs.technet.com/msrc/archive/2008/12/29/questions-about-vulnerability-claim-in-windows-media-player.aspx
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-189
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Wed Dec 24 2008 - 17:32:58 CST
MS Windows Media Player * (.WAV) Remote Integrer Overflow

Source: CCN
Type: The Microsoft Security Response Center (MSRC) Blog, Monday, December 29, 2008 12:02 PM
Questions about Vulnerability Claim in Windows Media Player

Source: CCN
Type: Security Vulnerability Research & Defense Blog, December 29, 2008 12:40 PM
Windows Media Player crash not exploitable for code execution

Source: MITRE
Type: CNA
CVE-2008-5745

Source: SREASON
Type: UNKNOWN
4823

Source: CCN
Type: SECTRACK ID: 1021495
Windows Media Player Integer Overflow in Playing WAV Files Lets Remote Users Deny Service

Source: CCN
Type: Microsoft Windows Media Player Web site
Microsoft Windows Media Player

Source: BUGTRAQ
Type: UNKNOWN
20081224 MS Windows Media Player * (.WAV) Remote Integrer Overflow

Source: BID
Type: Exploit
33018

Source: CCN
Type: BID-33018
RETIRED: Microsoft Windows Media Player WAV/MID/SND File Parsing Integer Overflow Vulnerability

Source: CCN
Type: BID-34534
RETIRED: Microsoft Windows Media Player MID File Parsing Integer Overflow Vulnerability

Source: CCN
Type: BID-34585
Microsoft Windows Media Player MIDI File Denial of Service Vulnerability

Source: CCN
Type: BID-34587
Microsoft Windows Media Player WAV File Multiple Denial of Service Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1021495

Source: XF
Type: UNKNOWN
win-mediaplayer-wav-snd-mid-dos(47664)

Source: XF
Type: UNKNOWN
win-mediaplayer-wav-snd-mid-dos(47664)

Source: EXPLOIT-DB
Type: UNKNOWN
7585

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:windows_media_player:9:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:windows_media_player:10:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:windows_media_player:11:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:windows_media_player:10:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:windows_media_player:9:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:windows_media_player:11:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft windows media player 9
    microsoft windows media player 10
    microsoft windows media player 11
    microsoft windows media player 10
    microsoft windows media player 9
    microsoft windows media player 11