Hackers targeting unpatched Microsoft DirectShow flaw

Article

Hackers targeting unpatched Microsoft DirectShow flaw

Microsoft released a security advisory Thursday warning of a new vulnerability in its DirectShow media-streaming architecture for Windows that could allow an attacker to execute code remotely.

The flaw, which Microsoft said is being actively exploited in limited attacks, affects Windows XP, Windows 2000, and Windows Server 2003. Windows Vista and Windows Server 2008 are not affected.

The vulnerability is in the QuickTime parser in DirectShow, according to Microsoft's Security Response Center.

"An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in email," Christopher Budd, security program manager at MSRC, wrote in a

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

blog post.

While the flaw isn't a browser vulnerability, "a browser-based vector is potentially accessible through any browser using media plug-ins that use DirectShow," he said. Also, it's possible to direct calls to DirectShow even if Apple's QuickTime is installed, he added.

An attacker who successfully exploits the vulnerability could gain the same user rights as the local user, according to Microsoft.

Microsoft posted workarounds in its advisory. More details on the workarounds are available from Microsoft's Security Research and Defense blog.