cbcvebase.
CVE-2007-6401
published 2007-12-17

CVE-2007-6401: Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers…

PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
29.73%
98.0th percentile
Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402.

Affected

4 ranges
VendorProductVersion rangeFixed in
3ivxmpeg-4_codec
3ivxmpeg-4_codec
guliverklimedia_player_classic
microsoftwindows_media_player

Detection & IOCsextracted from sources · hover to see the quote

filenamemplayer2.exe
  • Malicious .mp4 file delivered as a ZIP archive (PK magic bytes \x50\x4B\x03\x04) targeting mplayer2.exe / mplayerc.exe with 3ivx codec 4.5.1 or 5.0.1 installed; triggers stack-based buffer overflow on open.
  • Post-exploitation reverse shell binds on TCP port 49152; monitor for unexpected outbound or inbound connections on that port from media player processes.
  • Exploit targets Windows XP SP2; presence of 3ivx codec (3ivx_d4_451_win.exe or 5.0.1) combined with mplayer2.exe / mplayerc.exe 6.4.9 is a high-risk configuration.
  • ·CVE-2007-6402 (NVD doc) references mplayerc.exe (Media Player Classic 6.4.9) while the exploit targets mplayer2.exe (Windows Media Player 6.4); both share the same vulnerable 3ivx codec attack surface and are noted as possibly related to CVE-2007-6401.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.