Security Advisory

CVE-2007-3037

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-08-14 21:00:00
Last updated 2024-08-07 13:57:54
Assigner microsoft
State PUBLISHED

Description

Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka "Windows Media Player Code Execution Vulnerability Parsing Skins."