← Advisories

Media Player Classic 6.4.9.1 (iacenc.dll) DLL Hijacking Exploit

High
Advisory ID
ZSL-2010-4956
Release Date
26 August 2010
Affected Version
6.4.9.1 (revision 73)
Tested On
Microsoft Windows XP Professional SP3 (English)
Summary

Media Player Classic (MPC) is a compact media player for 32-bit Microsoft Windows. The application mimics the look and feel of the old, lightweight Windows Media Player 6.4 but integrates most options and features found in modern media players. It and its forks are standard media players in the K-Lite Codec Pack and the Combined Community Codec Pack.

Description

Media Player Classic suffers from a dll hijacking vulnerability that enables the attacker to execute arbitrary code on a local level. The vulnerable extensions are .mka, .ra and .ram thru iacenc.dll library.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
26.08.2010Initial release
27.08.2010Added reference [1], [2], [3], [4], [5], [6] and [7]
28.08.2010Added reference [8]
31.08.2010Added reference [9]
13.11.2010Added reference [10] and [11]
18.02.2011Added reference [12]
13.08.2013Added reference [13] and [14]