Microsoft on Monday denied reports of a critical vulnerability in its Windows Media Player. Redmond said the security researcher who reported an exploitable bug is mistaken.
Laurent Gaffie reported the bug on Christmas Eve via the Bugtraq e-mail list. Gaffie said Windows Media Player fails to handle an exceptional condition when parsing a malformed WAV, SND or MID file, and this flaw could lead to a remote integer overflow. Gaffie then offered proof-of-concept code. The bug reportedly affects all versions of Windows Media Player.
“The security researcher making the initial report didn’t contact us or work with us directly, but instead posted the report along with proof-of-concept code to a public mailing list,” said Christopher Budd, a spokesperson for the Microsoft Security Response Center. “After that report, other organizations picked the report up and claimed that the issue was a code-execution vulnerability in Windows Media Player. Those claims are false.”
Microsoft Goes Defensive
According to Budd, Microsoft found no possibility for code execution in this issue. Although the proof-of-concept code does trigger a crash of Windows Media player, he said the application can be restarted immediately and doesn’t affect the rest of the system.
“Unfortunately, the researcher chose not to come to us with this initial report. If he had, we would’ve done the exact same investigation we just completed,” Budd said. “When we were done, we would have let [him] know what we found, asked him if he thinks we might have missed something, continued the investigation if there was more information, and ultimately closed the case if we didn’t find a vulnerability. This is how we handle all of the cases we investigate with responsible researchers every year.”
Even when people choose not to report issues responsibly, Budd said Microsoft follows the same process: Launch an investigation to fully research the claims and…