Windows Media Player flaw denied
Security pantomime
Posted in Software & Security, 30th December 2008 10:41 GMT
Free whitepaper – Managing desktop software for fun and profit
Researchers reckon a security bug in Windows Media Player creates a means for hackers to inject hostile code onto vulnerable systems. However Microsoft has denied this, saying that the bug only creates a means to crash the software without posing a more damaging security risk.
The WMP integer overflow bug reportedly kicks in when the media player attempts to process maliciously constructed WAV, SND, or MIDI files. Security researchers have created proof of concept code demonstrating the vulnerability, the SANS Institute's Internet Storm Centre reports.
Fully patched Windows XP systems running either Windows Media Player 9 and 11 are each potentially vulnerable, according to tests by SecurityTracker. Other configurations may also be affected.
In a posting on Microsoft's Security Response blog, Redmond's security gnomes downplay the seriousness of the flaw, criticising researchers for spooking the internet community with what Microsoft charecterises as a premature disclosure. ®
Free whitepaper – Managing desktop software for fun and profit
Analyst Keynote: The Register Agile Data Center Summit
Dell PowerEdge R710 solution with VMware ESX vs. Dell PowerEdge 2850 solution
Seven ways to lower storage costs

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs