Advertisement
Promo

Online business Toolkit

Microsoft stomps on Media Player bug

Lisa M Bowman CNet

Published: 28 Jun 2002 08:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is warning people that a series of flaws in its Windows Media Player could allow a malicious hacker to hijack people's computer systems and perform a variety of actions.

The flaws, found in some anti-piracy and storage features of the software, affect Media Player for Windows XP and Media Player versions 6.4 and 7.1, according to a security bulletin on Microsoft's Web site.

The company rates the problems as "critical" -- Microsoft's most severe rating -- and urges people to "immediately" download a patch, which was released on Wednesday. The company said the patch would also fix previous problems with the software.

The patch is available here from ZDNet UK downloads.

In the most severe exploit of a flaw, a hacker could take over a computer system and perform any task the computer's owner is allowed to do, such as opening files or accessing certain parts of a network.

The flaw that's rated "critical" mishandles Windows Media Player's requests for media files containing "digital rights management" software, potentially allowing attackers access to Internet Explorer's cache, the place where temporary IE files are stored. The other flaws result from how the media player software responds to storage devices and the way it stores play lists.

To fall victim to an attack of the most severe kind, a person would have to obtain a media file, through email or by downloading it, for example. An attacker would then have to introduce an executable file into the person's browser cache and run it to gain access to the computer.

"It's not a straightforward, push-one-button-and-bad-things-happen type of thing. But there's a possibility a hacker could run code, and that's why we're rating it as critical," said Christopher Budd, a Microsoft security program manager.

Security holes have been a constant problem in Microsoft products, leading Chairman Bill Gates in January to promise to make security the company's top priority.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 80 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters