Vulnerability record · CVE-2003-0228 · published 27 May 2003
CVE-2003-0228: Windows Media Player skins directory traversal enables remote code execution
Microsoft · Windows Media Player
Windows Media Player 7.1 and the Windows XP version mishandle hex-encoded backslash characters (%5C) in skin file URLs, allowing directory traversal. A remote attacker can use a crafted skin to place an executable in an arbitrary location, which can then run with the user's privileges.
Description
Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit references and a high EPSS score, though the affected software is legacy and no KEV listing exists.
What it is
Windows Media Player 7.1 and the Windows XP version mishandle hex-encoded backslash characters (%5C) in skin file URLs, allowing directory traversal. A remote attacker can use a crafted skin to place an executable in an arbitrary location, which can then run with the user's privileges.
Impact
An attacker can write an executable to an arbitrary path on the victim's system and have it executed, giving code execution in the context of the logged-in user.
Attack surface
Reached remotely over the network via a malicious skin file or URL; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required, and exploitation depends on the victim opening or loading the crafted skin.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.463, 98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply Microsoft security bulletin MS03-017 or the corresponding vendor update for Windows Media Player.
- Upgrade to a supported Windows Media Player release, since 7.1 and the XP version are long out of support.
- Block or restrict loading of untrusted skin files and URLs in Media Player where policy allows.
- Educate users not to open skin files or media links from untrusted sources.
Detection
- Monitor for executable files created in unexpected directories shortly after Media Player processes a skin or URL.
- Alert on Media Player network activity or file writes involving skin files containing %5C sequences.
- Review process creation events where Media Player or a child process launches a newly written executable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0228 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0228), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.