SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5745

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3)…

MEDIUM 4.3EPSS 21.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 21.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
21.44% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
microsoft/windows media player
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.