CVE-2009-0555

Description

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media Speech codec, aka Windows Media Runtime Voice Sample Rate Vulnerability.

Risk Information

Base Score
9.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
EPSS Score
Exploitation Probability
31.948

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Media Format Runtime 9 for Windows 2000 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 2 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 2 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 2 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 3 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 3 (KB954155)Windows
Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 3 (KB954155)Windows
Security Update for Windows Media Format Runtime 9.5 for Windows Server 2003 (KB954155)Windows
Security Update for Windows Media Format Runtime 11 for Windows Vista (KB954155) x86 based systemsWindows
Security Update for Windows Media Format Runtime 11 for Windows Vista (KB954155) x86 based systems for SP1Windows
Security Update for Windows Media Format Runtime 11 for Windows Vista (KB954155) x86 based systems for SP2Windows
Security Update for Windows Media Format Runtime 11 for Windows Server 2008 (KB954155) x86 based systemsWindows
Security Update for Windows Media Format Runtime 11 for Windows Server 2008 (KB954155)Windows
Security Update for 32-bit Windows Media Format Runtime 9.5 for Windows XP x64 Edition (KB954155)Windows
Security Update for 32-bit Windows Media Format Runtime 9.5 for Windows Server 2003 x64 Edition (KB954155)Windows
Security Update for Windows Media Format Runtime 11 for Windows Vista for x64-based Systems (KB954155)Windows
Security Update for Windows Media Format Runtime 11 for Windows Vista for x64-based Systems (KB954155) for SP1Windows
Security Update for Windows Media Format Runtime 11 for Windows Vista for x64-based Systems (KB954155) for SP2Windows
Security Update for Windows Media Format Runtime 11 for Windows Server 2008 x64 Edition (KB954155)Windows
Security Update for Windows Media Format Runtime 11 for Windows Server 2008 x64 Edition (KB954155) for SP2Windows
Security Update for Windows XP (KB975025)Windows
Security Update for Windows Server 2003 (KB975025)Windows
Security Update for Windows XP x64 Edition (KB975025)Windows
Security Update for Windows Server 2003 x64 Edition (KB975025)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-7572Security Update for Windows Media Format Runtime 11 for Windows Vista (KB954155)
PATCH-7573Security Update for Windows Media Format Runtime 11 for Windows Server 2008 (KB954155)
PATCH-7582Security Update for Windows Media Format Runtime 11 for Windows Vista for x64-based Systems (KB954155)
PATCH-7583Security Update for Windows Media Format Runtime 11 for Windows Server 2008 x64 Edition (KB954155)
PATCH-7584Security Update for Windows Media Format Runtime 11 for Windows Server 2008 x64 Edition (KB954155)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234