Friday, May 29, 2009

Vulnerability In DirectShow Component Of DirectX

There has been found a vulnerability in DirectShow component of Microsoft DirectX. The vulnerability is related to handling of QuickTime media file. By luring a user to open specially crafted QuickTime media file an attacker may be able to execute arbitrary code in target system. According to Microsoft the vulnerability has been exploited in attacks.

Affected software:
* Windows 2000 SP4, DirectX 7.0, 8.1 and 9.0 versions
* Windows XP SP2 and SP3, DirectX 9.0 version
* Windows Server 2003 SP2, DirectX 9.0 version

Microsoft says that the vulnerability doesn't affect different versions of Windows Vista or Windows Server 2008.


More information (including available workarounds) can be read from correspondent Microsoft Security Advisory.

No comments: