peter bassill · operator
$ cve CVE-2004-1325 JSON

CVE-2004-1325 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 15.7% (pctl 97)

Patch early

A public exploit exists.

Description

The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS15.72% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-18
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwindows media player

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD