Windows Media Player 7 opens system for hackers

ITworld.com |  Development Add a new comment

A security vulnerability in Microsoft Corp.'s Windows Media Player 7 can allow a hacker to get full control over a user's computer, a well known bug hunter said.

According to Bulgarian security specialist Georgi Guninski the problem lies with the program's "skins," which allow the user to change the look and feel of the media player. Guninski published a security advisory on his Web site on Monday.

Microsoft confirmed the vulnerability. "A malicious Web site operator can embed a Java applet in a skin file. He can then use a script on a Web page to get access to the 'user's' computer," said Michael Aldridge, lead product manager for Microsoft's Windows Digital Media Division.

Upon being downloaded, the skins are installed on the user's system in a directory, or folder, with a commonly known name, Guninski said.

Guninski said in his advisory that the hacker could browse the system and execute arbitrary programs. This may lead to taking full control of the computer, he said. Guninski rates the vulnerability as "high risk."

Microsoft does not agree with Guninski's assessment. "We take every security issue seriously, but we characterize this as low risk," said Aldridge. "You should not download anything from a place you don't trust," he said, noting that the Web user has to accept the download of the file containing the malicious code.

Microsoft is working on a software patch for the problem. In the meantime it's safer not to download new skins for Windows Media Player from unknown sites.

There is also a workaround for the problem, said Aldridge -- disable the ability to run unsigned Java content. To do this select "Internet Options" in the "Tools" pull-down menu of Internet Explorer, select the "Security" tab and click on "Custom Level." Scroll down to "Java permissions," select "Custom Settings," click "Java Custom Settings," and select "Edit Permissions". Finally select "Disable" under "Run Unsigned Content."

This is not the first security hole found in Windows Media Player 7. Microsoft patched two flaws in the program in November last year. One of the issues also had to do with the skin feature of Windows Media Player.

Windows Media Player 7 is part of Microsoft's latest consumer edition of Windows, Windows Millennium Edition, and is available for free download from the company's Web site.

Guninski said he alerted Microsoft on Jan. 11.

Microsoft, in Redmond, Washington, can be reached at (425) 882-8080 or at www.microsoft.com. Georgi Guninski is at www.guninski.com.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    DevelopmentWhite Papers & Webcasts

    White Paper

    HP NonStop SQL Fundamentals whitepaper

    This whitepaper offers a detailed look into the fundamentals of HP NonStop SQL solutions. See how this system delivers unprecedented levels of application availability with fail-safe data integrity and meets the needs of enterprises with large-scale business critical applications.

    White Paper

    Nebraska Medical Center case study

    See how the Nebraska Medical Center implemented a SQL solution to make information more readily available to streamline operations, improve patient care and facilitate medical research with an enterprise solution running on HP NonStop servers.

    White Paper

    Concepts of NonStop SQL/MX

    For DBAs and developers who are familiar with Oracle solutions and want to learn about NonStop SQL/MX, this whitepaper provides an overview of the similarities and differences between the two products-with a specific focus on implementation.

    White Paper

    6 Things Your CIO Needs to Know About Requirements

    If your organization is not predictably successful on technology projects, there is likely an issue in requirements. CIOs must take action and own requirements maturity improvement. There are 6 main things a CIO must know about requirements.

    Webcast On Demand

    User Experience Monitoring

    In this webinar, you will learn hints & tips for improving end-user response times from Forrester Research analyst, Jean-Pierre Garbani.

    Sponsor: Nimsoft

    See more White Papers | Webcasts

    Ask a question

    Ask a Question