Feeds

Critical Windows vulnerability under attack, Microsoft warns

Drive-by web exploits possible

Beginner's guide to SSL certificates

Microsoft has warned of a critical security bug in older versions of its Windows operating system that is already being exploited in the wild to remotely execute malware on vulnerable machines.

The vulnerability in a Windows component known as DirectX is being targeted using booby-trapped QuickTime files, which when parsed can allow attackers to gain complete control of a computer. Because many browsers are designed to automatically play video, people can be compromised simply by visiting a site serving malicious files. Vista, Windows Server 2008 and the beta version of Windows 7 are not affected, and neither is Apple's QuickTime player, Microsoft said.

Microsoft has offered several work-arounds until a patch is available. The most straight-forward of them involves visiting this link and clicking on the "Fix it" icon. (We got an error when using Firefox, but it worked fine with Internet Explorer.) Several additional fixes are available on the work-arounds section here. The installation of QuickTime doesn't protect Windows users from being compromised.

The vulnerability exists in the way a DirectX application programming interface known as DirectShow handles supported QuickTime files. By manipulating the format, attackers can gain the same system privileges assigned to the logged-in user. Since Microsoft doesn't make it easy on users who log in to limited accounts, the vulnerability means most people using 2000, XP and Server 2003 versions of Windows are at risk of losing complete control of their machines.

Vista and later versions of Windows aren't affected because the vulnerable QuickTime parser filter was removed from them.

Microsoft was vague about the real-world attacks targeting the flaw except to say it "is aware of limited, active attacks that use this exploit code." It said it is sharing additional details with company partners through its Microsoft Active Protections Program, which was announced in August.

Microsoft has additional information here and here. ®

Beginner's guide to SSL certificates

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.