CVE-2003-0228

Microsoft Windows Media Player <7.1, XP - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jelmer Kuperus · javaremotewindows
https://www.exploit-db.com/exploits/22570

Scores

EPSS 0.7502
EPSS Percentile 98.9%

Details

Status published
Products (2)
microsoft/windows_media_player
microsoft/windows_media_player 7.1
Published May 27, 2003
Tracked Since Feb 18, 2026