5
CVSSv2

CVE-2004-1325

Published: 18/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote malicious users to determine the existence of files on the local system.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows media player 9

Exploits

source: wwwsecurityfocuscom/bid/12032/info The Windows Media Player ActiveX control is prone to a security weakness that may allow a malicious Web page to enumerate files that exist on the client computer This could aid in further attacks This issue is reported to affect Windows Media Player 9 It reportedly does not work on computers ...