Security Home > BackOffice Software > Windows Media Services

Malformed Media License Request Vulnerability

A denial of service vulnerability exists in Microsoft® Windows Media™ License Manager which could allow a malicious user to temporarily prevent the license server from issuing further licenses to customers for protected digital content (music and video).

Issue

Windows Media License Manager is part of Windows Media Rights Manager, a component of Windows Media Technologies that enables content providers to distribute copyrighted digital media in encrypted form. When Windows Media Player opens protected digital media, it contacts the provider’s server, presents the user’s license request information, and obtains a license that allows it to play the media. However, a specially-malformed license request can cause License Manager to halt, thereby preventing legitimate subscribers from obtaining a license for the same or other content hosted at this site.

The vulnerability does not in any way compromise the protection provided by the encryption or prevent offline playing of content that the user has already licensed. The server can be put back into normal operation by restarting the License Manager.

Affected Products

  • Microsoft Windows Media Rights Manager version 1.0

Download

Patch: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=19171

Further Details

Source: Microsoft Corporation

Reference: Microsoft Corporation

Updated: March 17, 2000

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<