Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Windows Media Player flaw could expose sensitive files

John McCormick

Published: 08 Jul 2003 15:46 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft's Media Player 9 has a vulnerability that could allow an attacker to play or modify media files on a target system. The big danger here is that many companies and even government agencies have begun to take advantage of fast network connections to move far beyond text email and make important announcements in video clips that are sent to employees. These clips often contain sensitive inside information. This flaw does not allow attackers to do more than tap into the files on the vulnerable systems, but that could be a devastating disclosure for some companies. MS03-021 addresses this threat.

Applicability
This ActiveX flaw is found in Media Player 9, but not in earlier versions of the software, including version 8.0, which ships with Windows XP. Media Player 9 ships with Windows Server 2003, but it can be downloaded and run on any Windows system using Windows 98 or later, so it may be found on any system where the user routinely downloads the latest versions of software updates.

According to Microsoft, "Systems Administrators who have deployed Windows Server 2003 as a Terminal Server would likely disable Internet Explorer Enhanced Security Configuration to allow users of the Terminal Server to utilize Internet Explorer in an unrestricted mode." That configuration would expose the system to this vulnerability.

Risk level
Since this Media Player flaw doesn't allow attackers to execute code or take over other system functions, Microsoft rates this as only a moderate threat. But depending on what is contained in your media files, the problem could be a dangerous disclosure risk. It is possible to use this vulnerability to alter, or view, media files.

Mitigating factors
This version of Media Player is mostly found in Windows Server 2003 systems, and many admins have probably made sure that the Media Player is disabled on that server OS. In addition, the default configuration of WS2K3 blocks this exploit.

Also, companies that do not make use of multimedia presentations or do not store them on vulnerable systems can probably ignore this threat.

Fix
Apply the patch released by Microsoft.

Final word
Organisations that use Windows Media Player files to distribute announcement videos to employees should consider streaming those files from a server rather than allowing employees to download them to their desktops. This would mitigate potential disclosure from this flaw. It would also better secure and protect any sensitive information in those files because it would keep them from being transferred to outside sources or being nabbed by hackers who find a way to compromise the network in another manner.

There is very little reason to run Windows Media Player on a server. So unless you need it for a specific task on Windows Server 2003, make sure it is disabled on all WS2K3 systems.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
21 out of 82 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

The Future of Humanitarian Technologie...

By Patrick Meier I had the distinct pleasure of co-authoring this major new United Nations Foundation & Vodafone Foundation Technology Report with my distinguished colleague Diane... More

Post a comment

On the Saving Edge: New Tech in Disast...

By Matthew Cordell A new report commissioned by the UN Foundation and Vodafone Foundation has found the intersection between two incredible trends -- the significant uptick in disasters... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV licence?... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters