News

Microsoft Updates Windows Media Player Patch

Microsoft published an update to a Windows Media Player patch on Tuesday, the same day as its January general security update release.

Microsoft published an update to a Windows Media Player patch on Tuesday, the same day as its January general security update release.

At issue is a glitch that results in an incomplete installation of December's MS08-076 Windows Media Component patch on Windows XP systems running Windows Media Format Runtime 9.5. The bulletin addendum, dated Jan. 13, is supposed to fix that glitch.

The revised bulletin also now lists Windows Media Player 6.4 and Windows Media Services 4.1 as affected for all editions of Microsoft Windows 2000 Service Pack 4 -- not just for Microsoft Windows 2000 Server SP4.

The update comes just weeks after Microsoft spokesperson Christopher Budd adamantly denied a report detailing a potential remote code execution hole in Windows Media Player. Security researcher Laurent Gaffi had described a vulnerability that could be used by hackers armed with malformed .wav, .snd, or .mid audio files to compromise a PC running Windows XP or Vista.

Budd negated that security claim, but he did confirm that Gaffi's proof-of-concept code could trigger a crash of the Windows-based app. Budd added that Windows Media Player can be restarted without harming the operating system. He suggested that the security update would fix the loose ends.

Researchers at Microsoft's Research and Defense group spelled out in mathematical and technological language how that the particular flaw mentioned by Gaffi is not a threat.

About the Author

James LaTour, MCSE, is a consultant for Trinity Consulting, a Microsoft Certified Gold Partner in Marlborough, Mass. He brings a wealth of health care experience to Trinity's HIPAA practice. In his spare time, he volunteers as webmaster and administrator for MARX7.org, the Massachusetts Area RX-7 and Rotary Powered Club, a non-profit automobile enthusiast club in the New England area. Reach him at JLaTour@Trinity-Inc.net.

Featured

  • Vendors Issue Patches for Linux Container Runtime Flaw Enabling Host Attacks

    This week, the National Institute of Standards and Technology (NIST) described a high-risk security vulnerability (CVE-2019-5736) for organizations using containers that could lead to compromised host systems.

  • Windows 10 Version 1809 Users May Get Visual Studio Crashes

    Microsoft on Friday issued an advisory for Windows 10 version 1809 users about possible Visual Studio crashes.

  • Standardizing the Look of Outlook's Outbound Messages

    Microsoft typically gives users a blank canvas to compose new e-mails in Outlook. In some corporate environments, however, a blank canvas isn't a good thing.

  • Windows 10 'Semiannual Channel Targeted' Goes Away This Spring

    Microsoft plans to slightly alter its Windows servicing lingo and management behavior with its next Windows 10 operating system feature update release, coming this spring.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.