Update Protection against Microsoft Browser Embedded Media Player Memory Corruption Vulnerability (MS10-082)
| Check Point Reference: | CPAI-2010-283 | |
| Date Published: | ||
| Severity: | ||
| Source: | Microsoft Security Bulletin MS10-082 | |
| Industry Reference(s): | CVE-2010-2745 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Windows Media Player 9 on Windows XP SP3
Windows Media Player 10 on:
Windows XP SP3
Windows XP Professional x64 Edition SP2
Windows Server 2003 SP2
Windows Server 2003 x64 Edition SP2
Windows Media Player 11 on:
Windows XP SP3
Windows XP Professional x64 Edition SP2
Windows Vista SP1
Windows Vista SP2
Windows Vista x64 Edition SP1
Windows Vista x64 Edition SP2
Windows Server 2008 for 32-bit Systems
Windows Server 2008 for 32-bit Systems SP2
Windows Server 2008 for x64-based Systems
Windows Server 2008 for x64-based Systems SP2
Windows Media Player 12 on:
Windows 7 for 32-bit Systems
Windows 7 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems
| ||
| Vulnerability Description A remote code execution vulnerability has been reported in Windows Media Player. Windows Media Player is a feature of the Windows operating system for personal computers. It is used for playing audio and video. A remote attacker may exploit this vulnerability to execute arbitrary code on a vulnerable system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS10-082 |
|
|
Vulnerability Details The vulnerability is due to an error in the Windows Media Player that improperly deallocates objects during a reload operation via a Web browser. A remote attacker could trigger this flaw by convincing a victim to enter a a malicious Web site. Successful exploitation of this issue may allow the attacker to take complete control of an affected system. |
Protection Overview
This protection will detect and block malformed browser plugin reloads.
In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense,go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.