PT-2009-1181 · Microsoft · Windows+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2 and SP3
Microsoft Windows Server 2003 SP2
Microsoft Windows Vista Gold, SP1, and SP2
Microsoft Windows Server 2008 Gold and SP2
Description
A stack-based buffer overflow exists in the
CComVariant::ReadFromStream() function within the Active Template Library (ATL), specifically affecting the MPEG2TuneRequest ActiveX control located in msvidctl.dll in DirectShow. A remote attacker can execute arbitrary code with the privileges of the logged-on user by inducing a user to view a specially crafted web page. This issue was exploited in the wild in July 2009.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
DoS
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Video Activex Control
Windows