Microsoft reports high-risk vulnerability in DirectX

By Angela Gunn | Published May 29, 2009, 6:27 AM

Pre-Vista versions of Windows are vulnerable to a hole in Microsoft DirectX that's currently under limited attack, the company has announced. The vulnerability in quartz.dll could allow an attacker to strike through QuickTime playback plug-ins for any browser using the affected platform.

The problem, according to the security advisory, lies in the QuickTime Movie Parser Filter that DirectShow uses to process files in that format, specifically in the quartz.dll file. It's available for exploitation even if the system doesn't have QuickTime installed. For the moment, there's no patch, but a post on Microsoft's Security Research & Defense blog details the currently recommended workarounds.

Comments

View comments by with a score of at least

As English is not my first language, I'm probably worng, but wouldn't it better if the start of the first paragraph was:

Pre-Vista version(s) of Windows.

Score: 0

|

Your English is just fine and you're not wrong at all, lastjuan (still love that username!). Corrected with thanks.

Score: 0

|

Saying it is in DirectX while accurate is blowing it out of proportions. Yes DirectShow is technically a part of DirectX; but so is DirectSound.

The QuickTime Movie Parser is more than 10 years old, I'm not at all surprised it has logic holes. Legacy code for a legacy feature.

Score: 1

|

Hell, DX9 is what...6 years old already?

Score: 0

|

True but we are talking about a feature that targeted Windows 95.

Score: 0

|

Which of course is why hackers are targeting it - it's a low-profile module which seems to have slipped through all of MS' security reviews.

Score: 2

|

.0b, 9.0c, countless security patches, and of course...

"Microsoft's Security Research & Defense blog details the currently recommended workarounds."

Yeah...they've done *nothing*... ;)

Let's not even bring up DX10 and 11, shall we?

Score: 0

|

Google Buzz: Another attempt to harness the content firehose

Similar to how Google successfully remolded RSS into a Google tool, the company now wants to remold Gmail into one big Google party

Success: Google's Nexus One shipping support line takes tech support questions

UPDATED Though the support line had been set up for shipping, it now appears Google personnel are happy to hear technical concerns.

Goodnight, moon: What I learned from a space shuttle

Carmi Levy | Wide Angle Zoom: Can the tech sector learn a few lessons from the space program? Certainly, if you believe in learning from someone else's mistakes.

Netflix to FCC: NBCU + Comcast could bypass net neutrality

Weaning itself from the post office as its main means of video transfer, Netflix would like someone to ensure the Internet remains just as unencumbered.

Rhapsody to become an independent company

RealNetworks and Viacom subsidiary MTV Networks have begun the process of spinning off music service Rhapsody into an independent company.

Nvidia debuts new dynamically-switched graphics card technology

Today, Nvidia announced that its Optimus technology for GPU switching will soon be available in a handful of Asus notebooks.

Google lowers 'unusually high' early termination fee on Nexus One

Google has lowered the Nexus One's early termination fees which were twice as high as the norm.

Netgear and Ericsson introduce a mobile broadband hotspot with a twist

It's a mobile broadband hotspot, but it's for use in the home.

Report: Streaming video drove 72% global increase in mobile data consumption

A new study says streaming video is "the single most influential factor driving the need for increased mobile network capacity."

Stymied by continuing Nexus One 3G issues, Google blames the environment

If you're still afflicted with the 3G flip-flop trouble, then you might consider moving. That appears to be the only suggestion Google can give for now.

Wolfram|Alpha makes a strong argument for virtual keyboards

"Answer engine" Wolfram|Alpha has updated its iPhone/iPod Touch app, harnessing the strength of the virtual keyboard.