Microsoft reports high-risk vulnerability in DirectX

By Angela Gunn | Published May 29, 2009, 6:27 AM

Pre-Vista versions of Windows are vulnerable to a hole in Microsoft DirectX that's currently under limited attack, the company has announced. The vulnerability in quartz.dll could allow an attacker to strike through QuickTime playback plug-ins for any browser using the affected platform.

The problem, according to the security advisory, lies in the QuickTime Movie Parser Filter that DirectShow uses to process files in that format, specifically in the quartz.dll file. It's available for exploitation even if the system doesn't have QuickTime installed. For the moment, there's no patch, but a post on Microsoft's Security Research & Defense blog details the currently recommended workarounds.

Comments

View comments by with a score of at least

As English is not my first language, I'm probably worng, but wouldn't it better if the start of the first paragraph was:

Pre-Vista version(s) of Windows.

Score: 0

|

Your English is just fine and you're not wrong at all, lastjuan (still love that username!). Corrected with thanks.

Score: 0

|

Saying it is in DirectX while accurate is blowing it out of proportions. Yes DirectShow is technically a part of DirectX; but so is DirectSound.

The QuickTime Movie Parser is more than 10 years old, I'm not at all surprised it has logic holes. Legacy code for a legacy feature.

Score: 1

|

Hell, DX9 is what...6 years old already?

Score: 0

|

True but we are talking about a feature that targeted Windows 95.

Score: 0

|

Which of course is why hackers are targeting it - it's a low-profile module which seems to have slipped through all of MS' security reviews.

Score: 2

|

.0b, 9.0c, countless security patches, and of course...

"Microsoft's Security Research & Defense blog details the currently recommended workarounds."

Yeah...they've done *nothing*... ;)

Let's not even bring up DX10 and 11, shall we?

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.