Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-0042


SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."


Published

2011-03-09T23:00:01.857

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft windows_xp_media_center 2005 Yes
Operating System microsoft windows_7 - Yes
Operating System microsoft windows_7 - Yes
Operating System microsoft windows_7 - Yes
Operating System microsoft windows_vista * Yes
Operating System microsoft windows_vista * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Application microsoft windows_media_center_tv_pack * Yes
Operating System microsoft windows_vista * Yes
Operating System microsoft windows_vista * Yes

References