CVE-2007-5095
Estado: ModificadaAlta (7.5)—
Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 15%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://osvdb.org/41093
- http://www.gnucitizen.org/blog/backdooring-windows-media-files
- http://www.securityfocus.com/archive/1/479825/100/100/threaded
- http://www.securityfocus.com/archive/1/479854/100/100/threaded
- http://www.securityfocus.com/archive/1/479855/100/100/threaded
- http://www.securityfocus.com/archive/1/479856/100/100/threaded
- http://osvdb.org/41093
- http://www.gnucitizen.org/blog/backdooring-windows-media-files
- http://www.securityfocus.com/archive/1/479825/100/100/threaded
- http://www.securityfocus.com/archive/1/479854/100/100/threaded
- http://www.securityfocus.com/archive/1/479855/100/100/threaded
- http://www.securityfocus.com/archive/1/479856/100/100/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-5095",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-09-26T22:17:00.000",
"references": [
{
"url": "http://osvdb.org/41093",
"source": "cve@mitre.org"
},
{
"url": "http://www.gnucitizen.org/blog/backdooring-windows-media-files",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479825/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479854/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479855/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479856/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41093",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gnucitizen.org/blog/backdooring-windows-media-files",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479825/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479854/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479855/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479856/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file."
},
{
"lang": "es",
"value": "Microsoft Windows Media Player (WMP) 9 sobre Windows XP SP2 llama a Internet Explorer en documentos HTML presentados dentro de algunos archivos media, sin importar cuál es el navegador web por defecto, lo cual podría permitir a atacantes remotos explotar vulnerabilidades en software que el usuario no esperaba ejecutar, como se demostro por el parámetro HTMLView en un archivo .asx."
}
],
"lastModified": "2026-06-16T22:45:26.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3778BBD3-6C58-46DF-B1EB-ED02513CA8D6"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}