01 June 2009 | 4,925 views

Hackers Exploiting Unpatched DirectX Bug With Quicktime

Check Your Web Security with Acunetix

It seems like another fairly critical flaw has been discovered in Microsoft Windows. It’s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned.

It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 and Windows 7 are not effected – so they have fixed the problem at some point in their development cycle, they just haven’t pushed it back to the older operating systems yet.

For the third time in the last 90 days, Microsoft Corp. has warned that hackers are exploiting an unpatched critical vulnerability in its software.

Late Thursday, Microsoft issued a security advisory that said malicious hackers were already using attack code that leveraged a bug in DirectX, a Windows subsystem crucial to games and used when streaming video from Web sites.

Hackers are using malicious QuickTime files — QuickTime is rival Apple Inc.’s default video format — to hijack PCs, Microsoft said. “The vulnerability could allow remote code execution if [the] user opened a specially crafted QuickTime media file,” the company said in the advisory. “Microsoft is aware of limited, active attacks that use this exploit code.”

According to Christopher Budd, a spokesman for the Microsoft Security Response Center, QuickTime itself is not flawed. Instead, the QuickTime parser in DirectShow, a component of DirectX, contains the bug. “An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail,,” Budd said in an entry on the MSRC blog.

Microsoft has had quite a spate of serious vulnerabilities recently, it seems resourceful hackers are targeting applications and components of the OS rather than the actual OS or networking stack.

Which makes sense, you’d expect the actual OS to be fairly secure now and not attention has been paid to those ‘must-have’ system softwares like DirectX.

Because the bug is in DirectShow, any browser using a plug-in that relies on DirectShow is also vulnerable.

DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk, Budd said, but Vista, Server 2008 and Windows 7 are not. “Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista,” Budd said.

Until a patch is available, users can protect their PCs by disabling QuickTime parsing. To do that requires editing the Windows registry, normally a task most users shy from, but Microsoft has automated the workaround. “We’ve gone ahead and built a ‘Fix it’ that implements the ‘Disable the parsing of QuickTime content in quartz.dll’ registry change,” Budd said. “We have also built a ‘Fix it’ that will undo the workaround automatically.”

Watch out when you are opening video files from unknown sources, especially in e-mail attachments (even from known sources) and you can use the ‘Fix it’ to mitigate against the problem until the patch is released.

Microsoft Security Advisory: Vulnerability in Microsoft DirectShow could allow remote code execution

Source: Network World



Recent in Exploits/Vulnerabilities:
- Sony Pictures Hacked – Employee Details & Movies Leaked
- Gruyere – Learn Web Application Exploits & Defenses
- Critical XSS Flaw Affects WordPress 3.9.2 And Earlier

Related Posts:
- FBI Unclassified E-mail Network Owned By Virus
- Active Exploitation Of Unpatched PDF Vulnerability
- Patch Window Shrinking – Semi-Automated Reverse Engineering

Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 228,453 views
- AJAX: Is your application secure enough? - 119,241 views
- eEye Launches 0-Day Exploit Tracker - 85,112 views

Advertise on Darknet

4 Responses to “Hackers Exploiting Unpatched DirectX Bug With Quicktime”

  1. Oki 1 June 2009 at 11:58 am Permalink

    Its strange how it was fixed in vista but no patch was released for the previous windows versions. It just looks like an attempt to get more users to switch to vista.

  2. T2t 1 June 2009 at 4:11 pm Permalink

    I agree it seems like one more thing to encourage us to “upgrade” to vista.

  3. Bogwitch 2 June 2009 at 9:18 am Permalink

    Bought my wife a nice new Vaio yesterday, first thing I did was to rip Vista off it.
    I’d like to say I installed Linux for her but alas, it is now WindowsXP.

    I am a little suprised that M$ did not issue the patch for previous versions. I’m sure thay would want more users switching to Vista but any M$ insecurity reflects poorly on them and provides that anti-M$ brigade with more ammunition.
    That said, I’m more suprised that M$ are actually putting much effort into Vista, I’m sure they have realised that it is just another WindowsME and should be focussing on getting Windows7 right.

  4. KaBaL 3 June 2009 at 3:10 pm Permalink

    The flaw really doesn’t hit that many target audiences though. As the majority of the populous running XP is going to have DirectX 9a installed. And I would assume the majority of business users aren’t going to have DirectX installed at all.

    But regardless – it comes down to the same thing – don’t open attachments / links to things you don’t know what they are! PERIOD! Lack of user education will the downfall of our society.