Title: Winamp Skin File (.WSZ) Local Zone Arbitrary Code Execution
Info
Disclosure
Aug 25, 2004
Discovery
Unknown
Dates
Exploit
Aug 25, 2004
Solution
Unknown
Description
WinAmp contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a user downloads a specifically crafted WinAmp skin from a malicious website. These skins are downloaded without prompting the user when using Internet Explorer. It is possible that the flaw may allow an attacker to to place and execute arbitrary programs resulting in a loss of confidentiality, integrity, or availability.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Uncoordinated Disclosure,
Discovered in the Wild
Solution
Upgrade to version 5.0.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.