Unrated severityNVD Advisory· Published Dec 31, 2003· Updated Apr 16, 2026
CVE-2003-1107
CVE-2003-1107
Description
The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.
Affected products
4cpe:2.3:a:microsoft:windows_media_player:6.4:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microsoft:windows_media_player:6.4:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:windows_media_player:7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:windows_media_player:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.kb.cert.org/vuls/id/222044nvdUS Government Resource
- support.microsoft.com/default.aspxnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/13375nvd
News mentions
0No linked articles in our index yet.