MS03-021: Windows Media Player Library Access (819639)

Medium Nessus Plugin ID 11774


Arbitrary code can be executed on the remote host through the media player.


An ActiveX control included with Windows Media Player 9 Series may allow a rogue website to gain information about the remote host.

An attacker could exploit this flaw to execute arbitrary code on this host with the privileges of the user running Windows Media Player.

To exploit this flaw, an attacker would need to set up a rogue website and lure a user of this host into visiting it.


Microsoft has released a set of patches for WMP 6.4, 7.1 and XP.

See Also

Plugin Details

Severity: Medium

ID: 11774

File Name: smb_nt_ms03-021.nasl

Version: $Revision: 1.43 $

Type: local

Agent: windows

Published: 2003/06/26

Modified: 2017/05/25

Dependencies: 57033, 13855, 16328

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:windows_media_player

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Excluded KB Items: SMB/Win2003/ServicePack

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2003/06/25

Vulnerability Publication Date: 2003/06/25

Reference Information

CVE: CVE-2003-0348

BID: 8034

OSVDB: 10997

MSFT: MS03-021

CERT: 320516

MSKB: 819639