Vulnerabilities / Threats
5/28/2009
05:48 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Microsoft Warns Of 'Browse-And-Get-Owned' DirectX Flaw

The flaw could allow a remote attacker to execute malicious code by convincing or duping a user to open a specially crafted QuickTime media file.

Microsoft on Thursday issued a security advisory stating that it's investigating reports of a vulnerability in Microsoft DirectX, the company's APIs for games and multimedia.

The company said that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are vulnerable and that Windows Vista and Windows Server 2008 are not vulnerable.

The flaw could allow a remote attacker to execute malicious code by convincing or duping a user to open a specially crafted QuickTime media file or to visit a Web page that features QuickTime media file of this sort.

The vulnerability is not in Apple's QuickTime media software or in Microsoft Internet Explorer browser; it's in the DirectShow platform (quartz.dll). Nonetheless, Web browsers -- Internet Explorer and others -- represent an avenue of potential infection for users of vulnerable versions of Windows.

"While the vulnerability is NOT in IE or other browsers, a browse-and-get-owned attack vector does exist here via the media playback plug-ins of browsers," Microsoft security software engineer Chengyun Chu explained in a post on the Microsoft Security Research and Defense (MSRC) blog. "The attacker could construct a malicious Web page which uses the media playback plug-ins to play back a malicious QuickTime file to reach the vulnerability in Quartz.dll."

A successfully executed attack would give the attacker the same file access rights as the affected user. For users with administrative rights, the risk is greater than for users with more restricted rights.

Microsoft said it "is aware of limited, active attacks that use this exploit code." Chu has posted several steps that users can take to protect themselves on the MSRC blog.

Earlier this month, Microsoft issued a security advisory about an authentication bypass vulnerability in certain Microsoft Internet Information Services configurations.


Black Hat is like no other security conference. It happens in Las Vegas, July 25-30. Find out more and register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0607
Published: 2014-07-24
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.

CVE-2014-1419
Published: 2014-07-24
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.

CVE-2014-2360
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage.

CVE-2014-2361
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

CVE-2014-2362
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.