Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Microsoft MPEG Layer-3 Codecs Memory Corruption Vulnerability

(MS10-052, CVE-2010-1882)

Vulnerability

A critical remote code execution vulnerability has been reported in the Microsoft DirectShow MP3 filter. Successful exploitation of this issue may allow the attacker take complete control of an affected system.

Details

Microsoft DirectShow is used for streaming media on Microsoft Windows operating systems, and performs client-side audio and video sourcing, manipulation and rendering within DirectX.  The vulnerability is within the MPEG Layer-3 Audio Codecs for Microsoft DirectShow (l3codecx.ax), which fail to properly handle specially crafted media files containing an MPEG Layer-3 audio stream. A remote attacker could trigger this flaw by convincing a victim to open a specially crafted MP3 file.

Affected Products

This vulnerability exists in Windows XP SP3, Windows XP Professional x64 Edition SP2, Windows Server 2003 SP2, and Windows Server 2003 X64 Edition SP2.

Solution

Check Point IPS Software Blade provides immediate network protection in the latest IPS Update by  detecting and blocking the transferring of malformed MP3 files over HTTP. For more information, see CPAI-2010-241.

Published August 10, 2010 

Legal Notice for Threat Center Advisories