Overview
The WMEX.DLL ActiveX control, which is installed by Windows Media Encoder 9 Series, contains a buffer overflow vulnerability.
Description
According to Microsoft, the Windows Media Encoder is a tool used to capture audio and video content using Windows Media. The WMEX.DLL ActiveX control contains a buffer overflow vulnerability. |
Impact
By convincing a user to view a specially crafted web page, an attacker may be able to execute arbitrary code with the privileges of the user. |
Solution
Apply an update Microsoft has published Microsoft Security Bulletin MS08-053 in response to this issue. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Microsoft credits Nguyen Minh Duc and Le Manh Tung, with Bach Khoa Internetwork Security Center (BKIS), Hanoi University of Technology (Vietnam), for reporting this vulnerability.
This document was written by John Hollenberger.
Other Information
CVE IDs: | CVE-2008-3008 |
Severity Metric: | 44.89 |
Date Public: | 2008-09-09 |
Date First Published: | 2008-09-09 |
Date Last Updated: | 2008-10-02 20:23 UTC |
Document Revision: | 17 |