Microsoft Warns About DirectX Exploit
Yesterday, the "Bringer of Bing" (aka Microsoft) issued a security advisory that reports on a new vulnerability in Microsoft DirectX, specifically in Microsoft DirectShow.
While DirectX security flaws are not uncommon, end-users generally receive alerts stemming from other Windows OS and Internet Explorer vulnerabilities; DirectX is usually associated with PC gaming. However, in the case of this incident, Microsoft says that the problem is limited, but remains quite active.
According to the company, the DirectX vulnerability allows remote code execution if the end-user opens a specially crafted QuickTime media file. Current investigations reveal that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are highly susceptible to an attack; Windows Vista and Windows Server 2008 are not vulnerable. Microsoft also said that if successful, the attacker could gain the same user rights as the local user. Consumers whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
"In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability," the company said, describing a mitigating factor. "An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to convince them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site. After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions."
While the company is currently working on a patch, Microsoft has provided an auto workaround here that can be used by way of a simple click. The fix actually disables QuickTime parsing automatically, however consumer who wish to do so manually will need to read the directions, as it involves altering the registry.
- Asus Fuses Together 2 GeForce GTX 285's
- Windows 7, Vista Downgrade to XP Rights Updated
- Dell Earnings Fall by 63 Percent, Waiting for Win 7
- Pixel Qi Demos Amazing E-Ink Laptop Screen
- An Update on AMD's Changing the Game
- Searching for Screensavers Risky, Viagra is Safe
- Google Wave is a Giant Social Noticeboard
- QOTD: Have You Ever Stolen Someone's WiFi?
- Intel: Atom is Eating into Celeron, and That's OK
- • 6 Awesome Robot Wars Match Ups
- • Billy Mays to Pitch Microsoft Zune HD
- • Sylvester Stallone Launches New WiFi Standard
- Intel/Psion Strike Deal Over "Netbook"
- Intel Announces New SU2700 CPU, GS40 Chipset
- Nvidia's Ion Makes a Splash at Computex 2009
- Report: HP, Dell to Launch Ion Machines in Q3
- Nvidia Tegra Promises 1080p Video, 25-day Music
- Intel's 'Larrabee' on Par With GeForce GTX 285





Bing!
An exploit via Quicktime... software developed by Apple. I can't even imagine how exploitable their OS is...
Hitokage an exploit using direct show could be rebuild for several other applications that rely on direct show.
As Apple's don't use DirectX (sadly otherwise the platform might be worth it) this exploit wont fly on Apple machines.
In other words this comes down to microsoft software being exploited not quicktime.
Hmm. Maybe Microsoft is doing some sneaky anti-Apple stuff? o.O
Apple is trying to infect all Windows machines to make people switch to Macs lol
Just sounds like Microsoft wants you to buy one of their new OS.
Apple is trying to infect all Windows machines to make people switch to Macs lol
Or Microsoft trying to infect XP users to make them upgrade to Vista/Win 7!
Quicktime sprites are a pain in the ass. Download one with them and at playback they can open whatever infected website they want.
I thought it was Bling
Just sounds like Microsoft wants you to buy one of their new OS.
I agree, and all while putting the blame on Apple. What a brilliant scheme.
Haha, when Microsoft sucks, it's Microsoft. When Apple sucks, it's Microsoft. I see I see.
And when XP sucks... well... we just pretend XP doesn't suck.
If you have Quicktime installed on your computer, you deserve much more then getting virus, you also need to be shot.
Just sounds like Microsoft wants you to buy one of their new OS.
Sure....its not as though Windows 7 is available as a free download or anything, right?...
Mac software on the PC has always been horible. There is about as much quality control in their PC software as there is in your toilet. A lot like Adobe now that I think about it...
Just sounds like Microsoft wants you to buy one of their new OS.
By working on a patch to fix the problem? Darn that evil Microsoft, somehow forcing me to buy a new OS by continuing to support and patch my current OS!
Current investigations reveal that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are highly susceptible to an attack; Windows Vista and Windows Server 2008 are not vulnerable.
Keep telling me how bad Vista is, and continue using XP. Everyone who has used a computer for 10 years or more, cannot deny that XP Sucked at launch. Hope they patch the exploit before any XP users get infected.