Description
Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player".
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5107
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A281
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-032
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/9420.php
Scores
EPSS
0.1442
EPSS Percentile
96.3%
Details
Status
published
Products (3)
microsoft/windows_media_player
microsoft/windows_media_player
6.4
microsoft/windows_media_player
7.1
Published
Jul 03, 2002
Tracked Since
Feb 18, 2026