9.3
CVSSv2

CVE-2007-6401

Published: 17/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote malicious users to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows media player 6.4

3ivx mpeg-4 codec 4.5.1

3ivx mpeg-4 codec 5.0.1

Exploits

#!/bin/perl # # Windows media player 64 MP4 Stack Overflow # # 0-day discovered and exploited by SYS 49152 # # Tested on win XP SP2 ENG # Shell on port 49152 # # usage: # - download this codec in order to manage MP4 content: # www3ivxcom/coral/3ivx_d4_451_winexe # # - open the MP4 file with mplayer2exe # # SYS 49152 # gforce(put ...