(MS10-094) Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961)
Publish Date: 10 février 2011
Gravité: : Élevé
Identifiant(s) CVE: : CVE-2010-3965
Date du conseil: 10 février 2011
Description
This update resolves a vulnerability in Windows Media Encoder, which could allow remote code execution if an attacker succeeds in convincing users to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. More specifically, this update addresses the vulnerability by correcting the way the Windows Media Encoder loads external libraries.
Information Exposure Rating:
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
Solutions
Affected software and version:
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Vista Service Pack 1
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 1
- Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for x64-based Systems Service Pack 2