[38038] in bugtraq
Windows Media files allow opening any url in Internet Explorer
daemon@ATHENA.MIT.EDU (Berend-Jan Wever)
Sat Jan  1 14:42:59 2005
Message-ID: <13147.213.148.227.187.1104604821.squirrel@www.edup.tudelft.nl>
Date: Sat, 1 Jan 2005 19:40:21 +0100 (CET)
From: "Berend-Jan Wever" <skylined@edup.tudelft.nl>
To: bugtraq@securityfocus.com, full-disclosure@lists.netsys.org
Reply-To: skylined@edup.tudelft.nl
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-1
Content-Transfer-Encoding: 8bit
PC World has published an interesting article:
http://www.pcworld.com/news/article/0,aid,119016,00.asp
Short version:
The Digital Rights Management for Windows Media files allows opening
arbitrary urls in Internet Explorer.
Impact:
MSIE browser vulnerabilities can now be exploited through wma files,
allowing virii, worms and other kinds of malware to spread through P2P
networks.
Happy new year!
Cheers,
SkyLined