Microsoft DirectShow Remote Code Execution Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
29 May 2009
5211
Views
RISK: Medium Risk
A vulnerability in Microsoft DirectX that could allow remote code execution if user opened a specially crafted QuickTime media file.
Impact
- Remote Code Execution
System / Technologies affected
- DirectX 7.0 on Microsoft Windows 2000 Service Pack 4
- DirectX 8.1 on Microsoft Windows 2000 Service Pack 4
- DirectX 9.0 on Microsoft Windows 2000 Service Pack 4
- DirectX 9.0 on Windows XP Service Pack 2 and Windows XP Service Pack 3
- DirectX 9.0 on Windows XP Professional x64 Edition Service Pack 2
- DirectX 9.0 on Windows Server 2003 Service Pack 2
- DirectX 9.0 on Windows Server 2003 x64 Edition Service Pack 2
- DirectX 9.0 on Windows Server 2003 with SP2 for Itanium-based Systems
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Note: There is no patch available for this vulnerability currently.
Workaround:
Please refer to the workaround provided by the vendor.
http://www.microsoft.com/technet/security/advisory/971778.mspx
Vulnerability Identifier
Source
Related Link
Share with