Heap-based Buffer Overflow in Microsoft Windows Media Player due to Skin File Vulnerability
CVE-2007-3037

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 August 2007

Summary

A vulnerability in Microsoft Windows Media Player allows remote attackers to execute arbitrary code by sending a specially crafted skin file (WMZ or WMD). A size mismatch issue occurs due to discrepancies between compressed data and the size of the decompressed data, leading to a heap-based buffer overflow. This vulnerability affects various versions of Windows Media Player, posing significant risks if exploited by attackers.

References

EPSS Score

59% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.