Microsoft DirectShow AVI Invalid biCrlUsed Value (IMAP4 Base64)

Strike ID:
E10-01301
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2010

Description

This strike triggers a vulnerability when an AVI file containing a video chunk with an invalid biCrlUsed value is used in a GraphEdt.exe AVI/WAVE File Source filter, then that filter's video pin is connected to the input pin of an AVI Splitter filter. NOTE: While the malicious file transferred over the network by this strike is required to trigger the vulnerability, actually triggering the vulnerability requires a considerable amount of user interaction with the malicious file within GraphEdt.exe.

CVE

Bid