Description
Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise."
References (6)
Core 6
Core References
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/591890
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104025849109384&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6427
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10892
US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2002-37.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-072
Scores
EPSS
0.2342
EPSS Percentile
97.6%
Details
Status
published
Products (1)
microsoft/windows_xp
(6 CPE variants)
Published
Dec 26, 2002
Tracked Since
Feb 18, 2026