OCX Attachment Vulnerability
A security vulnerability exists in a OCX control, associated with Windows Media Player, that could cause certain email applications to fail, requiring the user to restart the e-mail client to resume normal operation.
Issue
OCX controls are containers that can hold multiple ActiveX controls. A particular OCX control, associated with Windows Media Player, could be used in a denial of service attack against RTF-enabled e-mail clients such as Microsoft® Outlook and Outlook Express. If the affected control were programmatically embedded into an RTF mail and then sent to another user, the user’s mail client would fail when he closed the mail.
The vulnerability would not cause any lasting effects. The user could resume normal operation by restarting the mail client and deleting the affected mail. Although the affected OCX control is associated with Windows Media Player, it poses no threat to it – the vulnerability could only be used to attack e-mail clients.
Affected Products
- Microsoft Windows Media Player 7
Download
Patch: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24421
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: September 26, 2000
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
















