Advertisement
Promo

Online business Toolkit

Microsoft stomps on Media Player bug

Lisa M Bowman CNet

Published: 28 Jun 2002 08:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is warning people that a series of flaws in its Windows Media Player could allow a malicious hacker to hijack people's computer systems and perform a variety of actions.

The flaws, found in some anti-piracy and storage features of the software, affect Media Player for Windows XP and Media Player versions 6.4 and 7.1, according to a security bulletin on Microsoft's Web site.

The company rates the problems as "critical" -- Microsoft's most severe rating -- and urges people to "immediately" download a patch, which was released on Wednesday. The company said the patch would also fix previous problems with the software.

The patch is available here from ZDNet UK downloads.

In the most severe exploit of a flaw, a hacker could take over a computer system and perform any task the computer's owner is allowed to do, such as opening files or accessing certain parts of a network.

The flaw that's rated "critical" mishandles Windows Media Player's requests for media files containing "digital rights management" software, potentially allowing attackers access to Internet Explorer's cache, the place where temporary IE files are stored. The other flaws result from how the media player software responds to storage devices and the way it stores play lists.

To fall victim to an attack of the most severe kind, a person would have to obtain a media file, through email or by downloading it, for example. An attacker would then have to introduce an executable file into the person's browser cache and run it to gain access to the computer.

"It's not a straightforward, push-one-button-and-bad-things-happen type of thing. But there's a possibility a hacker could run code, and that's why we're rating it as critical," said Christopher Budd, a Microsoft security program manager.

Security holes have been a constant problem in Microsoft products, leading Chairman Bill Gates in January to promise to make security the company's top priority.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 80 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

3 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters