Advice and Information, Tutorials and Guides > Security Alerts & warnings

Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution

(1/1)

Derek:
http://www.microsoft.com/technet/security/advisory/971778.mspx


--- Quote ---Microsoft is investigating new public reports of a new vulnerability in Microsoft DirectX. The vulnerability could allow remote code execution if user opened a specially crafted QuickTime media file. Microsoft is aware of limited, active attacks that use this exploit code. While our investigation is ongoing, our investigation so far has shown that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are vulnerable; all versions of Windows Vista and Windows Server 2008 are not vulnerable. Microsoft has activated its Software Security Incident Response Process (SSIRP) and is continuing to investigate this issue
--- End quote ---

further details
http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx

Navigation

[0] Message Index

Go to full version