GFI
English Deutsch Français Italiano Nederlands Español
GFI SecurityLabs > Nieuws 2000 > Security flaw discovered in Windows Media ...

Security flaw discovered in Windows Media Player 7

Can be blocked by mail essentials email content checking gateway

London, UK, 23 November 2000 - GFI, developer of email content checking & network security software, has discovered a security flaw within Windows Media Player 7 which allows a malicious user to run arbitrary code on a victim's machine as it attempts to view a web site or an HTML email. GFI has notified Microsoft Corp., which issued an advisory (Microsoft security Bulletin number MS00-090).

Windows Media Player 7 is included by default on Windows Millennium Editions and is available from Microsoft for free. It includes skinning capabilities that allow it to change interface. GFI has found that this can be exploited to execute code on remote machines.

"The exploit works simply by opening an email on a machine which includes Windows Media Player 7 and on which HTML scripts are allowed, or by browsing a malicious site," warned GFI security engineer, Sandro Gauci.

"This security problem is exploited by embedding a JavaScript (.js) file within a Media Player skin file (.wmz) which can also be embedded in a Windows Media Download file (.wmd). This does not require the user to run any attachments since the Media Player file is automatically executed using an iframe tag or a window.open() with in a

Over GFI
GFI is een toonaangevende ontwikkelaar van software voor netwerkbeveiliging, inhoudsbeveiliging en messaging. Dankzij bekroonde technologie, een agressieve prijsstrategie en een sterke focus op MKB-bedrijven helpt GFI bedrijven over de hele wereld om maximale continuïteit en productiviteit te bewerkstelligen. GFI is opgericht in 1992 en heeft kantoren in Malta, Londen, Raleigh, Hong Kong en Adelaide die wereldwijd meer dan 200.000 installaties ondersteunen. GFI is een kanaalgericht bedrijf met meer dan 10.000 partners over de hele wereld. GFI is ook een Microsoft Gold Certified Partner. Meer informatie over GFI is te vinden op http://www.gfi.nl.
 
Alle genoemde product- en bedrijfsnamen zijn mogelijk handelsmerken van hun respectievelijke eigenaren.



 Lees meer over de producten van GFI
>  GFI MailEssentials for Exchange/SMTP
>  GFI MailSecurity for Exchange/SMTP
>  GFI MailArchiver for Exchange
>  GFI FAXmaker for Exchange/SMTP
>  GFI LANguard Network Security Scanner
>  GFI EventsManager
>  GFI EndPointSecurity
>  GFI Network Server Monitor
>  GFI WebMonitor for ISA Server

   © 2008. Alle rechten voorbehouden. GFI Software Home Producten Downloads Ondersteuning Bestellen Site map Over GFI Contact