Sploitus

Exploit for Windows Media Player plugin EMBED buffer overflow

saint · 2006-02-16

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:1690948909D4A644619AB3BCC68614E6
Added: 02/16/2006  
CVE: [CVE-2006-0005](<https://vulners.com/cve/CVE-2006-0005>)  
BID: [16644](<http://www.securityfocus.com/bid/16644>)  
OSVDB: [23132](<http://www.osvdb.org/23132>)  


### Background

The Windows Media Player plug-in allows the processing of embedded media from inside other applications, such as web browsers. 

### Problem

A buffer overflow in the Windows Media Player plug-in allows remote command execution when a long EMBED tag is processed by a non-Microsoft Internet browser. 

### Resolution

Install the patch referenced in [Microsoft Security Bulletin 06-006](<http://www.microsoft.com/technet/security/Bulletin/MS06-006.mspx>). 

### References

<http://www.microsoft.com/technet/security/Bulletin/MS06-006.mspx>  


### Limitations

Exploit works on Mozilla Firefox 1.5.0.1 on Windows. 

### Platforms

Windows