Web Browser Vulnerability in Microsoft Windows Media Player on Windows XP
CVE-2007-5095

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
26 September 2007

Summary

Microsoft Windows Media Player 9 on Windows XP SP2 has a security configuration that invokes Internet Explorer to render HTML documents embedded in certain media files. This occurs independently of the user's default web browser settings, potentially allowing remote attackers to exploit existing vulnerabilities in the software that the user does not anticipate executing. This is exemplified by the manipulation of the HTMLView parameter in an .asx file, which can lead to unauthorized actions or data exposure.

References

EPSS Score

27% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.