Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-0372


Vulnerability Score 7.5 7.5
CVE Id CVE-2002-0372
Last Modified 10 Sep 2008 08:01:02
Published 03 Jul 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player".

Vulnerable Systems


  • Microsoft Windows Media Player 6.4

  • Microsoft Windows Media Player 7.1

  • Microsoft Windows Media Player Xp


MS - MS02-032

BID - 5107

XF - mediaplayer-cache-code-execution(9420)

Last Updated: 27 May 2016 10:36:53