main
Report a problem

Critical Bug In Legacy Windows Media Players

Tom Warren   on 11 December 2006 - 08:52 · 36 comments & 15026 views

Advertisement (Why?)
Proof-of-concept code that exploits a critical bug in Windows Media Player has gone public, Microsoft Corp. warned users late Thursday.

A vulnerability in Media Player 9 and 10 can be used by attackers to grab control of a PC, security researchers warned. A malicious .asx-formatted playlist, if opened by an unsuspecting user, could completely compromise the machine.

"We're aware of proof-of-concept code published publicly affecting Windows Media ASX file format [and] we are currently investigating," wrote Alexandra Huft, a security program manager with the Microsoft Security Response Center, on the team's blog. "We are not currently aware of attempts to exploit this vulnerability," she added.

Because .asx playlists open automatically within a browser, hackers would only need to coax users to a malicious Web site to snatch their systems. Microsoft has offered no workarounds or other tactical advice.

View: TechWeb Story

Post a comment · Send to friend Comments · There are 36 additional comments
(6 replies) #1 Active-X on 11 Dec 2006 - 09:12
Upgrade to WMP11...this seems to be good solution right now
#1.1 Fubar on 11 Dec 2006 - 09:17
or use winamp
#1.2 Active-X on 11 Dec 2006 - 09:22
din dong
#1.3 Active-X on 11 Dec 2006 - 09:23
Quote - Fubar said @ #1.1
or use winamp

itunes, anyone ?
#1.4 rbet on 11 Dec 2006 - 09:34
Quote - Active-X said @ #1.3
Quote - Fubar said @ #1.1
or use winamp

itunes, anyone ?


no.
#1.5 +King Mustard on 11 Dec 2006 - 11:27
Quote - rbet said @ #1.4
Quote - Active-X said @ #1.3
Quote - Fubar said @ #1.1
or use winamp

itunes, anyone ?


no.

lol
#1.6 Active-X on 11 Dec 2006 - 11:54
[quote=King Mustard said,#1.5][quote=rbet said,#1.4][quote=Active-X said,#1.3][quote=Fubar said,#1.1]or use winamp [/quote]
itunes, anyone ?[/quote]

no.[/quote]

thnk GOD...
(6 replies) #2 Sp3ctranova on 11 Dec 2006 - 09:15
I'd upgrade to WMP11 if I didn't hate it's interface so much
#2.1 MajinDark on 11 Dec 2006 - 09:16
That's a lame excuse. Use a skin if you don't like the default interface.
#2.2 o0o o0o on 11 Dec 2006 - 09:20
Quote - MajinDark said @ #2.1
That's a lame excuse. Use a skin if you don't like the default interface.


okay so wmp10 skin exist for wmp11?

if no then wmp10 for life
#2.3 noroom on 11 Dec 2006 - 09:56
Quote - MajinDark said @ #2.1
That's a lame excuse. Use a skin if you don't like the default interface.

That doesn't fix it, because when it's embedded in a website, it still looks like crap.

Also, there's a whooping what, 50 skins to choose from? Yay. Winamp > WMP.
#2.4 mcloum on 11 Dec 2006 - 10:39
Quote - noroom said @ #2.3

That doesn't fix it, because when it's embedded in a website, it still looks like crap.



But it doesnt, when its embedded in a website it look just like the other version of media player but with different colours!

#2.5 noroom on 11 Dec 2006 - 17:20
Quote - mcloum said @ #2.4
Quote - noroom said @ #2.3

That doesn't fix it, because when it's embedded in a website, it still looks like crap.



But it doesnt, when its embedded in a website it look just like the other version of media player but with different colours!

Um, and the buttons look different. And they're in different positions. Which means, it looks different. Like crap.
#2.6 faraaz on 12 Dec 2006 - 03:40
Quote - noroom said @ #2.5
Quote - mcloum said @ #2.4
Quote - noroom said @ #2.3

That doesn't fix it, because when it's embedded in a website, it still looks like crap.



But it doesnt, when its embedded in a website it look just like the other version of media player but with different colours!

Um, and the buttons look different. And they're in different positions. Which means, it looks different. Like crap.


IMHO, WMP 11 is so much better. i dont understand how you can hate it so much
(2 replies) #3 Pc_Madness on 11 Dec 2006 - 09:30
Considering WMP9 is abit of a struggle on my laptop, upgrading to 11 will suck :
#3.1 Rahul on 11 Dec 2006 - 09:55
dont worry it sux as it is
#3.2 MioTheGreat on 11 Dec 2006 - 14:31
No it doesn't. WMP11 is quite nice (Certainly beats iTunes, not that that is hard to do.)
#4 +Xerxes on 11 Dec 2006 - 10:39
Bit hard to upgrade my Win2k machine, since WMP9 was the last to support 2k (my main machine is XP though)
(5 replies) #5 Cheruman on 11 Dec 2006 - 11:28
<typical mac user troll post>Another day, another M$ security hole. Why do people bother with this crap - I use a Mac, which not only means my computer is safe from all security threats, but it makes me better than the rest of you unwashed plebs.</typical mac user troll post>
#5.1 Bamsebjørn on 11 Dec 2006 - 11:47
<mr. obvious>You're being a troll, sir...</mr. obvious>
#5.2 ikyouCrow on 11 Dec 2006 - 12:56
<typical pc user post>so how's flip4mac performing there?</typical pc user post>
#5.3 spacer on 11 Dec 2006 - 13:08
Quote - Cheruman said @ #5
...Why do people bother with this crap...

Counter-Strike.
#5.4 AMDMEFX-55 on 11 Dec 2006 - 15:05
He is just mad cause only a hand full of people use Mac's. Anyway why do ppl hate on WMP11 I like it much better then WMP10.
#5.5 +M2Ys4U on 11 Dec 2006 - 22:46
Quote - AMDMEFX-55 said @ #5.4
He is just mad cause only a hand full of people use Mac's. Anyway why do ppl hate on WMP11 I like it much better then WMP10.


Me too, I don't get the WMP11 hating. It's actually a lot better once you get used to the change.
#6 Havin_it on 11 Dec 2006 - 12:30
They don't mention privilege escalation, so unless someone uses it for a ransomware payload my beloved work PCs are safe, I guess... still, I might now do a proper study on whether we can upgrade to WMP11 -- I'm sure the users want to anyway :/
(5 replies) #7 spacer on 11 Dec 2006 - 13:14
after reading:

"We are not currently aware of attempts to exploit this vulnerability," she added.

Did anyone else ask themselves, "If no one knew about it or has been trying to exploit it, then why tell people about it BEFORE you fix it? Just fix it, THEN tell people about it. Don't give hackers any heads-up on the subject."

sheesh
#7.1 Andareed on 11 Dec 2006 - 14:42
The details were likely already released on a security forum. Script kiddies are more likely to read such forums than MS press releases imo.
#7.2 hvy on 11 Dec 2006 - 14:53
Quote - spacer said @ #7
after reading:

"We are not currently aware of attempts to exploit this vulnerability," she added.

Did anyone else ask themselves, "If no one knew about it or has been trying to exploit it, then why tell people about it BEFORE you fix it? Just fix it, THEN tell people about it. Don't give hackers any heads-up on the subject."

sheesh


MS WANTS people to upgrade to WMP11, for the DRM and commercial ties.
#7.3 Danrarbc641 on 11 Dec 2006 - 15:19
Quote - hvy said @ #7.2
Quote - spacer said @ #7
after reading:

"We are not currently aware of attempts to exploit this vulnerability," she added.

Did anyone else ask themselves, "If no one knew about it or has been trying to exploit it, then why tell people about it BEFORE you fix it? Just fix it, THEN tell people about it. Don't give hackers any heads-up on the subject."

sheesh


MS WANTS people to upgrade to WMP11, for the DRM and commercial ties.

Can you give me an example of where WMP11 enforces DRM moreso than, say, WMP10?
#7.4 Croquant on 11 Dec 2006 - 18:49
Quote - Danrarbc641 said @ #7.3
Quote - hvy said @ #7.2
Quote - spacer said @ #7
after reading:

"We are not currently aware of attempts to exploit this vulnerability," she added.

Did anyone else ask themselves, "If no one knew about it or has been trying to exploit it, then why tell people about it BEFORE you fix it? Just fix it, THEN tell people about it. Don't give hackers any heads-up on the subject."

sheesh


MS WANTS people to upgrade to WMP11, for the DRM and commercial ties.

Can you give me an example of where WMP11 enforces DRM moreso than, say, WMP10?

Actualy, WMP 11 has "online store" features that only work with the Zune player, so Microshcloft wants to scare everyone into getting WMP 11 becasue they think it will lead to more Zune sales.
#7.5 +Brandon Live on 11 Dec 2006 - 20:31
Quote - Croquant said @ #7.4
Quote - Danrarbc641 said @ #7.3
Quote - hvy said @ #7.2
Quote - spacer said @ #7
after reading:

"We are not currently aware of attempts to exploit this vulnerability," she added.

Did anyone else ask themselves, "If no one knew about it or has been trying to exploit it, then why tell people about it BEFORE you fix it? Just fix it, THEN tell people about it. Don't give hackers any heads-up on the subject."

sheesh


MS WANTS people to upgrade to WMP11, for the DRM and commercial ties.

Can you give me an example of where WMP11 enforces DRM moreso than, say, WMP10?

Actualy, WMP 11 has "online store" features that only work with the Zune player, so Microshcloft wants to scare everyone into getting WMP 11 becasue they think it will lead to more Zune sales.


Wrong wrong wrong. Zune has its own software. It has no tie-ins with WMP 11 at all (which is actually a common gripe among WMP 11 users).
(1 reply) #8 soldier1st on 11 Dec 2006 - 20:47
the drm crap is the only reason i wont upgrade to wmp11 so i will stick to winamp/wmp10 ty.the interface in 11 is good just like wmp10,9 is not as good.
#8.1 RealFduch on 11 Dec 2006 - 22:13
Well... maybe when you grow a bit you'll understand your mistakes.
(1 reply) #9 Sp3ctranova on 12 Dec 2006 - 07:51
You know what...after all this I went and downloaded the latest WMP11. It's going to take some getting used to but it's time I sucked up my dislike of WMP11 and got with the future. It's playing now as we speak.
And you know? The interface is actually decent. The only thing that really bugged me was the way the Library is layed out, but with the Details view it's actually similar to WMP10, which is all I really cared about.

I don't plan to buy a Zune; Archos makes much better products.
I don't plan on using WMP's music stores; I prefer iTunes (and other sources).
I may as well just get used to WMP11. It's here to stay.
#9.1 +M2Ys4U on 12 Dec 2006 - 11:29
Once I got used to the new layout I found that it was significantly better to use then WMP10 and below. It just took a little time to familiarise myself
#10 XPGoD on 12 Dec 2006 - 22:05
Sadly the PoC looks like someone was bored...

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)