MS10-093: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434)
High Nessus Plugin ID 51165
SynopsisThe remote Windows host is affected by a remote code execution vulnerability.
DescriptionThe remote Windows host is missing a security update. It is, therefore, affected by a flaw in Windows Movie Maker due to a failure to correctly restrict the path being used for loading external libraries. An unauthenticated, remote attacker can exploit this to execute arbitrary code with the user's privileges by convincing the user to open a specially crafted Windows Movie Maker (.mswmm) file that is located in the same network directory as a specially crafted dynamic link library (DLL) file.
SolutionMicrosoft has released a set of patches for Windows Vista.