You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided.
Description
Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling Rate Vulnerability."
Evaluator Description
http://www.microsoft.com/technet/security/Bulletin/MS08-054.mspx
Security updates are available from Microsoft Update, Windows Update, and Office Update. Security updates are also available from the Microsoft Download Center. You can find them most easily by doing a keyword search for "security update.
*Windows Server 2008 server core installation not affected. The vulnerability addressed by this update does not affect supported editions of Windows Server 2008 if Windows Server 2008 was installed using the Server Core installation option, even though the files affected by this vulnerability may be present on the system. However, users with the affected files will still be offered this update because the update files are newer (with higher version numbers) than the files that are currently on your system. For more information on this installation option, see Server Core. Note that the Server Core installation option does not apply to certain editions of Windows Server 2008; see Compare Server Core Installation Options.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to nvd@nist.gov.
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:2008:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:2008:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:2008:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:2008:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows-nt:xp:*:*:*:gold:*:x64:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:pro:*:x64:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
Changed
Reference Type
http://marc.info/?l=bugtraq&m=122235754013992&w=2 Mailing List
http://marc.info/?l=bugtraq&m=122235754013992&w=2 Mailing List, Third Party Advisory
Changed
Reference Type
http://www.securityfocus.com/bid/30550 Broken Link
http://www.securityfocus.com/bid/30550 Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.vupen.com/english/advisories/2008/2522 Broken Link
http://www.vupen.com/english/advisories/2008/2522 Third Party Advisory
Changed
Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5615 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5615 Third Party Advisory
CVE Modified by Microsoft Corporation9/28/2017 9:31:04 PM
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:window
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:2008:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:window
Changed
Reference Type
http://marc.info/?l=bugtraq&m=122235754013992&w=2 No Types Assigned
http://marc.info/?l=bugtraq&m=122235754013992&w=2 Mailing List
Changed
Reference Type
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5615 No Types Assigned
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5615 Not Applicable
Changed
Reference Type
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766863#PRODUCTS No Types Assigned
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=766863#PRODUCTS Broken Link
Changed
Reference Type
http://www.microsoft.com/technet/security/Bulletin/MS08-054.mspx No Types Assigned
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:window
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:2008:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:window
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:window
Configuration 1
AND
OR
*cpe:2.3:a:microsoft:windows_media_player:11:*:*:*:*:*:*:*
OR
cpe:2.3:o:microsoft:windows-nt:xp:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:pro:x64:*:*:*:*
cpe:2.3:o:microsoft:window
Initial CVE Analysis9/11/2008 10:09:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2008-2253 NVD
Published Date: 09/10/2008 NVD
Last Modified: 10/30/2018
Source: Microsoft Corporation