SB2017111422 - Information disclosure in Microsoft Windows Media Player
Published: November 14, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2017-11768)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists in Windows Media Player due to improper disclosure of file information when handling user-supplied input. A local attacker can execute an application that submits malicious input to access sensitive information on the targeted system, which could be used to conduct additional attacks.
Remediation
Install update from vendor's website.