Author Topic: Extremely critical 0-day exploit of Microsoft DirectX  (Read 3923 times)

0 Members and 1 Guest are viewing this topic.

Alan Baxter

  • Guest
Extremely critical 0-day exploit of Microsoft DirectX
« on: June 05, 2009, 06:39:20 PM »
I posted this in another tech forum last week, and I don't remember seeing it posted here too.  I apologize for my tardiness.  Until today, I rationalized it would be fixed next Tuesday, but thanks to Bob's post, I realize this vulnerability is not going to be fixed in Tuesday's patches.  The following post contains a link to Microsoft's temporary (I hope) FixIt to work around this vulnerability and exploit.  I strongly encourage anyone with a vulnerable system to enable the workaround ASAP.  Windows Vista is not vulnerable.

-----------------------------------------------------------------
2009-05-29 - Extremely critical 0-day exploit of Microsoft DirectX
Does not appear to affect all versions of Windows Vista and Windows Server 2008
Secunia Advisory http://secunia.com/advisories/35268/
Microsoft workaround http://support.microsoft.com/kb/971778
According to Microsoft, the vulnerability does not require QuickTime
Affects:
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Storage Server 2003
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Extremely critical 0-day exploit of Microsoft DirectX
« Reply #1 on: June 05, 2009, 07:15:53 PM »
Hi Alan Baxter,

Was also treated in this thread, and I gave a link to a fix here: http://forum.avast.com/index.php?topic=45800.msg383813#msg383813 (and also to undo the fix when the real patch will be there),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Alan Baxter

  • Guest
Re: Extremely critical 0-day exploit of Microsoft DirectX
« Reply #2 on: June 05, 2009, 07:24:29 PM »
Thank you, polonus.  I'm glad Marc57 was more prompt than me.  I must have seen it here last Monday but forgotten about it.  Pretty obvious warning, now that you've pointed me to it.  ;D

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Extremely critical 0-day exploit of Microsoft DirectX
« Reply #3 on: June 05, 2009, 09:31:22 PM »
What does QuickTime have to do with a DirectX vulnerability? ???
"People who are really serious about software should make their own hardware." - Alan Kay

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48564
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Extremely critical 0-day exploit of Microsoft DirectX
« Reply #4 on: June 05, 2009, 10:57:19 PM »
What does QuickTime have to do with a DirectX vulnerability? ???


"Microsoft today warned that hackers are using rigged QuickTime media files to exploit an unpatched vulnerability in DirectShow,
the APIs used by Windows programs for multimedia support."
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Extremely critical 0-day exploit of Microsoft DirectX
« Reply #5 on: June 08, 2009, 02:37:12 AM »
Just adding this: http://www.f-secure.com/weblog/archives/00001695.html

Seems they may have spmething good going on with that exploit shield of theirs.
"People who are really serious about software should make their own hardware." - Alan Kay