Patch Available for Windows Media Player Skins File Download Vulnerability (287045)



The information in this article applies to:

  • Microsoft Windows Media Player 7

This article was previously published under Q287045

SYMPTOMS

Microsoft has released a patch that eliminates a security vulnerability in Windows Media Player 7. This vulnerability could potentially allow a malicious user to cause a program of his or her choice to run on another user's computer.

Windows Media Player 7 includes a feature called "skins" that you can use to customize the look and feel of Windows Media Player. If a Windows Media Player skin (.wmz) file were downloaded from a malicious Web site, the file could potentially be used to run Java code to read and browse files on the local computer. The vulnerability exists because "skins" are downloaded to a known location on a computer and are stored in a .zip package. If the .zip package contained a Java class (.class) file, any Java code in the class could be run in the local computer security zone.

If a Windows Media Player skin (.wmz) file were downloaded from a malicious Web site, it could potentially cause the deployment of zipped Java code to a known location on the visiting user's computer. Because the Java code would reside in a known location on the computer, script that is hosted on a malicious Web site or that is embedded in a malicious HTML e-mail message could potentially invoke the script in the local computer security zone to take arbitrary action on the local computer.

RESOLUTION

A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that you determine are at risk of attack. Evaluate your computer's physical accessibility, network and Internet connectivity, and other factors to determine the degree of risk to your computer. See the associated Microsoft Security Bulletin to help determine the degree of risk. This fix may receive additional testing. If your computer is sufficiently at risk, Microsoft recommends that you apply this fix now. Otherwise, wait for the next Windows Media Player 7 update (which will be made available by using the Check For Player Upgrades mechanism in Windows Media Player 7) that contains this fix.

To resolve this problem immediately, download the fix by following the instructions later in this article or contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

The following file is available for download from the Microsoft Download Center:
NOTE: This update also corrects the problems discussed in the following Microsoft Knowledge Base article:

280419 Patch Available for ".asx Buffer Overrun" and ".wms Script Execution" Vulnerabilities

For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to Obtain Microsoft Support Files from Online Services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file. The English version of this fix should have the following file attributes or later:
   Date        Time    Version     Size       File name
   -------------------------------------------------------
   02/06/2001  12:44p  7.0.0.1959    827,664  Wmpcore.dll
   02/06/2001  12:51p  7.0.0.1959    348,432  Wmplayer.exe
   02/06/2001  12:51p  7.0.0.1959  1,134,864  Wmpui.dll
				

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

MORE INFORMATION

For additional information about this vulnerability, please see the following Microsoft web site: For additional information about how to install Windows 2000 and Windows 2000 hotfixes at the same time, click the article number below to view the article in the Microsoft Knowledge Base:

249149 Installing Microsoft Windows 2000 and Windows 2000 Hotfixes


Modification Type:MajorLast Reviewed:4/21/2003
Keywords:kbfix kbgraphxlinkcritical kbprb kbQFE KB287045