CVE-2004-1324
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 16.65% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows media player
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110352518211306&w=2
- http://www.securityfocus.com/bid/12031Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18576
- http://marc.info/?l=bugtraq&m=110352518211306&w=2
- http://www.securityfocus.com/bid/12031Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18576
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.