Vulnerabilities > CVE-2004-1325 - Unspecified vulnerability in Microsoft Windows Media Player 9

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microsoft
exploit available

Summary

The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Exploit-Db

descriptionWindows Media Player 9.0 ActiveX Control File Enumeration Weakness. CVE-2004-1325. Remote exploit for windows platform
idEDB-ID:25032
last seen2016-02-03
modified2004-12-18
published2004-12-18
reporterArman Nayyeri
sourcehttps://www.exploit-db.com/download/25032/
titleWindows Media Player 9.0 - ActiveX Control File Enumeration Weakness