Hackers Exploiting Unpatched DirectX Bug With Quicktime

It seems like another fairly critical flaw has been discovered in Microsoft Windows. It’s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned.

It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 and Windows 7 are not effected – so they have fixed the problem at some point in their development cycle, they just haven’t pushed it back to the older operating systems yet.

For the third time in the last 90 days, Microsoft Corp. has warned that hackers are exploiting an unpatched critical vulnerability in its software.

Late Thursday, Microsoft issued a security advisory that said malicious hackers were already using attack code that leveraged a bug in DirectX, a Windows subsystem crucial to games and used when streaming video from Web sites.

Hackers are using malicious QuickTime files — QuickTime is rival Apple Inc.’s default video format — to hijack PCs, Microsoft said. “The vulnerability could allow remote code execution if [the] user opened a specially crafted QuickTime media file,” the company said in the advisory. “Microsoft is aware of limited, active attacks that use this exploit code.”

According to Christopher Budd, a spokesman for the Microsoft Security Response Center, QuickTime itself is not flawed. Instead, the QuickTime parser in DirectShow, a component of DirectX, contains the bug. “An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail,,” Budd said in an entry on the MSRC blog.

Microsoft has had quite a spate of serious vulnerabilities recently, it seems resourceful hackers are targeting applications and components of the OS rather than the actual OS or networking stack.

Which makes sense, you’d expect the actual OS to be fairly secure now and not attention has been paid to those ‘must-have’ system softwares like DirectX.

Because the bug is in DirectShow, any browser using a plug-in that relies on DirectShow is also vulnerable.

DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk, Budd said, but Vista, Server 2008 and Windows 7 are not. “Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista,” Budd said.

Until a patch is available, users can protect their PCs by disabling QuickTime parsing. To do that requires editing the Windows registry, normally a task most users shy from, but Microsoft has automated the workaround. “We’ve gone ahead and built a ‘Fix it’ that implements the ‘Disable the parsing of QuickTime content in quartz.dll’ registry change,” Budd said. “We have also built a ‘Fix it’ that will undo the workaround automatically.”

Watch out when you are opening video files from unknown sources, especially in e-mail attachments (even from known sources) and you can use the ‘Fix it’ to mitigate against the problem until the patch is released.

Microsoft Security Advisory: Vulnerability in Microsoft DirectShow could allow remote code execution

Source: Network World

Posted in: Exploits/Vulnerabilities, Malware, Windows Hacking

, , , , , ,

Latest Posts:

SecLists - Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells SecLists – Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.
DeepSound - Audio Steganography Tool DeepSound – Audio Steganography Tool
DeepSound is an audio steganography tool and audio converter that hides secret data into audio files, the application also enables you to extract from files.
2019 High Severity Vulnerabilities What are the MOST Critical Web Vulnerabilities in 2019?
So what is wild on the web this year? Need to know about the most critical web vulnerabilities in 2019 to protect your organization?
GoBuster - Directory/File & DNS Busting Tool in Go GoBuster – Directory/File & DNS Busting Tool in Go
GoBuster is a tool used to brute-force URIs (directories and files) in web sites and DNS subdomains (inc. wildcards) - a directory/file & DNS busting tool.
BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.

4 Responses to Hackers Exploiting Unpatched DirectX Bug With Quicktime

  1. Oki June 1, 2009 at 11:58 am #

    Its strange how it was fixed in vista but no patch was released for the previous windows versions. It just looks like an attempt to get more users to switch to vista.

  2. T2t June 1, 2009 at 4:11 pm #

    I agree it seems like one more thing to encourage us to “upgrade” to vista.

  3. Bogwitch June 2, 2009 at 9:18 am #

    Bought my wife a nice new Vaio yesterday, first thing I did was to rip Vista off it.
    I’d like to say I installed Linux for her but alas, it is now WindowsXP.

    I am a little suprised that M$ did not issue the patch for previous versions. I’m sure thay would want more users switching to Vista but any M$ insecurity reflects poorly on them and provides that anti-M$ brigade with more ammunition.
    That said, I’m more suprised that M$ are actually putting much effort into Vista, I’m sure they have realised that it is just another WindowsME and should be focussing on getting Windows7 right.

  4. KaBaL June 3, 2009 at 3:10 pm #

    The flaw really doesn’t hit that many target audiences though. As the majority of the populous running XP is going to have DirectX 9a installed. And I would assume the majority of business users aren’t going to have DirectX installed at all.

    But regardless – it comes down to the same thing – don’t open attachments / links to things you don’t know what they are! PERIOD! Lack of user education will the downfall of our society.