Integer underflow in Microsoft Windows and Windows Server - CVE-2020-1239

 

Integer underflow in Microsoft Windows and Windows Server - CVE-2020-1239

Published: June 9, 2020 / Updated: June 10, 2020


Vulnerability identifier: #VU28846
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1239
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer underflow in mpg2splt.ax module of Windows Media Player. A remote attacker can ass specially crafted data to the application, trigger integer underflow and execute arbitrary code on the target system.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2020-1239

Install update from vendor's website.


External References

Related Security Bulletins