Critical Windows vulnerability under attack, Microsoft warns

by iambest | May 29, 2009 at 02:17 am
38 views | 4 Recommendations | 0 comments

Photos

Microsoft appreciates Macromedia

Microsoft appreciates Macromedia

see larger image

uploaded by Brajeshwar

Microsoft has warned of a critical security bug in older versions of its Windows operating system that is already being exploited in the wild to remotely execute malware on vulnerable machines.

The vulnerability in a Windows component known as DirectX is being targeted using booby-trapped QuickTime files, which when parsed can allow attackers to gain complete control of a computer. Because many browsers are designed to automatically play video, people can be compromised simply by visiting a site serving malicious files. Vista, Windows Server 2008 and the beta version of Widows 7 are not affected, and neither is Apple's QuickTime player, Microsoft said.

Microsoft has offered several work-arounds until a patch is available. The most straight-forward of them involves visiting this link and clicking on the "Fix it" icon. (We got an error when using Firefox, but it worked fine with Internet Explorer.) Several additional fixes are available on the work-arounds section here. The installation of QuickTime doesn't protect Windows users from being compromised.

The vulnerability exists in the way a DirectX application programming interface known as DirectShow handles supported QuickTime files. By manipulating the format, attackers can gain the same system privileges assigned to the logged-in user. Since Microsoft doesn't make it easy on users who log in to limited accounts, the vulnerability means most people using 2000, XP and Server 2003 versions of Windows are at risk of losing complete control of their machines.

Comments (0)

This story was created over 3 months ago, the comment thread is now closed.

What is NowPublic?

NowPublic lets people work together to cover news events around the world.

Find out more

Crowd Power

Anonymous
First Flagged at 4:57 AM, May 29, 2009 by Anonymous (not verified)
These members have powered this story:

Most Recommended Stories in Tech & Biz

Recommendations (4)

Most recently recommended by:
 

closeSign in to NowPublic

is reporting from