Microsoft Windows 'MPEG2TuneRequest' Object Remote Code Execution Vulnerability (972890)

  Severity: MEDIUM
  Advisory Date: APR 05, 2012

  DESCRIPTION

Microsoft Windows is prone to a remote code-execution vulnerability that affects the TV Tuner library. A malicious user could exploit this issue by enticing a victim to visit a maliciously crafted Web site. Successfully exploiting this issue would allow the malicious user to execute arbitrary code in the context of the currently logged-in user.

  TREND MICRO PROTECTION INFORMATION

Trend Micro Deep Security shields the following vulnerabilities using the specified rules. Trend Micro customers using OfficeScan with the Intrusion Defense Firewall plugin are also protected from attacks using these vulnerabilities.

Microsoft Bulletin ID Vulnerability ID Rule Number & Title Deep Security Pattern Version Deep Security Pattern Release Date

CVE-2008-0015 1003609 - COM Object Instantiation Memory Corruption - July 2009 09-020 July 7, 2009

CVE-2008-0015 1003606 -Microsoft Windows 'MPEG2TuneRequest' Object Remote Code Execution 09-020 July 7, 2009

CVE-2008-0015 1003605 - Microsoft Windows 'MPEG2TuneRequest' Object Remote Code Execution Vulnerability 09-020 July 7, 2009

IDF filter identifiers are provided by Third Brigade.

  AFFECTED SOFTWARE AND VERSION

  • Microsoft Windows XP
  • Microsoft Windows XP 64-Bit Edition
  • Microsoft Windows XP 64-Bit Edition Service Pack 1
  • Microsoft Windows XP 64-Bit Edition Version 2003
  • Microsoft Windows XP 64-Bit Edition Version 2003 Service Pack 1
  • Microsoft Windows XP Gold Service Pack 1
  • Microsoft Windows XP Home Edition
  • Microsoft Windows XP Home Edition Service Pack 1
  • Microsoft Windows XP Home Edition Service Pack 2
  • Microsoft Windows XP Home Edition Service Pack 3
  • Microsoft Windows XP Media Center Edition
  • Microsoft Windows XP Media Center Edition Service Pack 1
  • Microsoft Windows XP Media Center Edition Service Pack 2
  • Microsoft Windows XP Media Center Edition Service Pack 3
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Professional Service Pack 1
  • Microsoft Windows XP Professional Service Pack 2
  • Microsoft Windows XP Professional Service Pack 3
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows XP Professional x64 Edition Service Pack 2
  • Microsoft Windows XP Professional x64 Edition Service Pack 3
  • Microsoft Windows XP Tablet PC Edition
  • Microsoft Windows XP Tablet PC Edition Service Pack 1
  • Microsoft Windows XP Tablet PC Edition Service Pack 2
  • Microsoft Windows XP Tablet PC Edition Service Pack 3

Featured Stories