iTnews
  • Home
  • News
  • Technology
  • Security

Experts warn of Media Player vulnerability

By Shaun Nichols
Dec 12 2006 9:46AM
Follow google news

Specially crafted Media Player .asx file could be used to gain control.

Experts warn of Media Player vulnerability
A newly discovered security vulnerability in Windows Media Player has prompted security firms to warn users to remain extra vigilant and alter the way they handle a certain type of file.

According to a Microsoft security advisory, an attacker could use a specially crafted Media Player .asx file to gain control of a user's system and remotely execute malware. 

The file could be placed in an HTML file, causing it to be automatically launched by the user's web browser.

Microsoft has confirmed the vulnerability and said that it is investigating the issue.

Secunia has given the vulnerability a rating of 'highly critical', the security firm's second highest alert level. 

Originally disclosed on 22 November, and thought to cause only a denial-of-service attack, security research firm EEye now believes that exploit code could be written for the vulnerability. 

EEye suggests that users can mitigate the threat by changing the default application to load .asx files. 

WatchGuard security analyst Corey Nachreiner, however, believes that users should not panic over the vulnerability. 

In a posting to WatchGuard's newswire feed entitled 'Unpatched Windows Media Player vulnerability announced; world fails to end,' Nachreiner downplays the immediate urgency of the flaw.

"While I do not doubt EEye's findings, there is a big difference between a flaw assumed to allow code execution and one confirmed to allow code execution, " he said.

Nachreiner pointed out that the Media Player vulnerability does not pose as serious a threat to users as the currently unpatched and active Word exploit.

The analyst still recommends users to follow EEye's steps to mitigate the effect of the vulnerability.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
expertsmediaofplayersecurityvulnerabilitywarn

Related Articles

  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
  • Defence says Palantir is "sandboxed" in its environment Defence says Palantir is "sandboxed" in its environment
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.