Microsoft Warns About DirectX Exploit
Yesterday, the "Bringer of Bing" (aka Microsoft) issued a security advisory that reports on a new vulnerability in Microsoft DirectX, specifically in Microsoft DirectShow.
While DirectX security flaws are not uncommon, end-users generally receive alerts stemming from other Windows OS and Internet Explorer vulnerabilities; DirectX is usually associated with PC gaming. However, in the case of this incident, Microsoft says that the problem is limited, but remains quite active.
According to the company, the DirectX vulnerability allows remote code execution if the end-user opens a specially crafted QuickTime media file. Current investigations reveal that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are highly susceptible to an attack; Windows Vista and Windows Server 2008 are not vulnerable. Microsoft also said that if successful, the attacker could gain the same user rights as the local user. Consumers whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
"In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability," the company said, describing a mitigating factor. "An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to convince them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site. After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions."
While the company is currently working on a patch, Microsoft has provided an auto workaround here that can be used by way of a simple click. The fix actually disables QuickTime parsing automatically, however consumer who wish to do so manually will need to read the directions, as it involves altering the registry.
- Asus Fuses Together 2 GeForce GTX 285's
- Windows 7, Vista Downgrade to XP Rights Updated
- Dell Earnings Fall by 63 Percent, Waiting for Win 7
- Pixel Qi Demos Amazing E-Ink Laptop Screen
- An Update on AMD's Changing the Game
- Searching for Screensavers Risky, Viagra is Safe
- Google Wave is a Giant Social Noticeboard
- QOTD: Have You Ever Stolen Someone's WiFi?
- Intel: Atom is Eating into Celeron, and That's OK
- • Billy Mays to Pitch Microsoft Zune HD
- Alienware's "Allpowerful" Laptop is the M17x
- • Sylvester Stallone Launches New WiFi Standard
- Intel/Psion Strike Deal Over "Netbook"
- Intel Announces New SU2700 CPU, GS40 Chipset
- Nvidia's Ion Makes a Splash at Computex 2009
- Report: HP, Dell to Launch Ion Machines in Q3
- Nvidia Tegra Promises 1080p Video, 25-day Music
- Intel's 'Larrabee' on Par With GeForce GTX 285





Who the hell uses Quick time...eewww.
Anyone with an iPod , iTouch or iPhone as it's an integral part of iTunes
Using it and having it installed and hence being vunerable are 2 different things.
I have Quicktime installed, but I've messed with Opera so that Quicktime isn't allowed to run in-browser. I prefer it this way. Why the hell do I want MP3s to play in a media player... in my browser?
Who the hell uses Quick time...eewww. Damn right