Microsoft reports high-risk vulnerability in DirectX

By Angela Gunn | Published May 29, 2009, 6:27 AM

Pre-Vista versions of Windows are vulnerable to a hole in Microsoft DirectX that's currently under limited attack, the company has announced. The vulnerability in quartz.dll could allow an attacker to strike through QuickTime playback plug-ins for any browser using the affected platform.

The problem, according to the security advisory, lies in the QuickTime Movie Parser Filter that DirectShow uses to process files in that format, specifically in the quartz.dll file. It's available for exploitation even if the system doesn't have QuickTime installed. For the moment, there's no patch, but a post on Microsoft's Security Research & Defense blog details the currently recommended workarounds.

Comments

View comments by with a score of at least

As English is not my first language, I'm probably worng, but wouldn't it better if the start of the first paragraph was:

Pre-Vista version(s) of Windows.

Score: 0

|

Your English is just fine and you're not wrong at all, lastjuan (still love that username!). Corrected with thanks.

Score: 0

|

Saying it is in DirectX while accurate is blowing it out of proportions. Yes DirectShow is technically a part of DirectX; but so is DirectSound.

The QuickTime Movie Parser is more than 10 years old, I'm not at all surprised it has logic holes. Legacy code for a legacy feature.

Score: 1

|

Hell, DX9 is what...6 years old already?

Score: 0

|

True but we are talking about a feature that targeted Windows 95.

Score: 0

|

Which of course is why hackers are targeting it - it's a low-profile module which seems to have slipped through all of MS' security reviews.

Score: 2

|

.0b, 9.0c, countless security patches, and of course...

"Microsoft's Security Research & Defense blog details the currently recommended workarounds."

Yeah...they've done *nothing*... ;)

Let's not even bring up DX10 and 11, shall we?

Score: 0

|

Microsoft unveils a host of Windows Phone 7 Series developer tools

Today, Microsoft announced the availability of Windows Phone Developer Tools, a beta of Expression Blend 4, and the release candidate of Silverlight 4

Silverlight 4 RC, the Windows Phone 7 platform, downloadable today

What was released last year as the next Web video platform has transformed into the sole functionality platform for Microsoft's next mobile platform.

IE9, Windows Phone, Silverlight: What can we expect from Microsoft at MIX?

We've heard about three screens and a cloud. Then four screens, or three-and-a-half, and a cloud. Or two. Today, will there be five of one and two of the other?

Android vs. iPhone vs. BlackBerry vs. OS X vs. Windows, brought to you by Namco

Namco, one of video gaming's most iconic brands, today announced a new cross-platform game engine called UniteSDK, which will let gamers play with one another irrespective of the platform they're playing their games on.

Google: No word yet on China pullout, negotiations continue

No, Google has not said whether it is exiting the country. But the key to understanding this episode, on both sides, is to parse the meaning of "said."

The missing dimension in 3D TV

Carmi Levy | Wide Angle Zoom: For an industry where Blu-ray is already fizzling, is one movie with blue people enough to launch a product line?

Italy launches a beta of Microsoft Tags for tourism

Today, Northern Italian city of Turin (Torino) announced it is the first city to use Microsoft Tag as a solution for tourism.

Again, it's over: Microsoft loses second review of Word appeal

An Appeals Court ruling Wednesday continues an old legal precedent: When you can't estimate the extent of an injury, $200 million is as sound as any other figure.

In a more complicated gaming world, OpenGL 4.0 gets simpler, smarter

Game developers are gearing up for the latest update to the world's cross-platform 3D shading language, with hopes that it has caught up with DirectX 11.

FCC releases iPhone app to learn more about network conditions

Create a more accurate National Broadband Plan by submitting network reports to the FCC.

Early praise for Google Maps' bike routes

The reason some folks travel by car to go less than a mile is because they say they know where they're going that way. Now Google removes that excuse.