Sploitus

Exploit for Windows Media Player plugin EMBED buffer overflow

saint · 2006-02-16

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:9328EEE04FE799CF2C8D0D8EFDDE76F7
Added: 02/16/2006  
CVE: CVE-2006-0005  
BID: 16644  
OSVDB: 23132  


### Background

The Windows Media Player plug-in allows the processing of embedded media from inside other applications, such as web browsers. 

### Problem

A buffer overflow in the Windows Media Player plug-in allows remote command execution when a long EMBED tag is processed by a non-Microsoft Internet browser. 

### Resolution

Install the patch referenced in Microsoft Security Bulletin 06-006. 

### References

http://www.microsoft.com/technet/security/Bulletin/MS06-006.mspx   


### Limitations

Exploit works on Mozilla Firefox 1.5.0.1 on Windows. 

### Platforms

Windows