|
|
Security Check Details
MS10-016: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561) Synopsis :
Arbitrary code can be executed on the remote host through Windows
Movie Maker.
Description :
The remote Windows host contains a version of Windows Movie Maker
that is affected by a buffer overflow vulnerability due to the way
the application parses project file formats.
If an attacker can trick a user on the affected system into open a
specially crafted Movie Maker or Producer file using the affected
application, he may be able to leverage this issue to execute
arbitrary code subject to the user's privileges.
Solution :
Microsoft has released a set of patches for Windows XP, Vista, and
7 :
http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx
Risk factor :
High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
More at Nessus.org
|
|
|