Winamp Skin File Arbitrary Code Execution Vulnerability

“A vulnerability has been reported in Winamp, which can be exploited by malicious people to compromise a user’s system. The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction. An XML document in the Winamp skin zip file can reference a HTML document using the ‘browser’ tag and get it to run in the ‘Local computer zone.’ This can be exploited to run an executable program embedded in the Winamp skin file using the ‘object’ tag and the ‘codebase’ attribute.”

Article Written by

Chris has consistently expressed his convictions and visions outright, supplying practical information to targeted audiences: media agencies, business owners, technology consumers, software and hardware professionals, et al. He remains a passionate personality in the tech community-at-large. He's a geek.