All the latest UK technology news, reviews and analysis

Microsoft flaw exploits music files

by Iain Thomson

More from this author

24 Jul 2003

Be the first to comment

  • Tweet this

Microsoft has warned of a critical flaw in its DirectX multimedia software that could allow a hacker to take control of a PC via a music file.

The company has warned that buffer overruns are possible due to two flaws in its DirectShow software, part of DirectX.

DirectShow handles sound and video, and the flaw can be exploited by either sending a specially prepared Midi file as an email attachment, or by embedding it in a web page.

"Many users will not see multimedia files like this as hostile," said Integralis penetration tester Pete Philips.

"This makes it more likely that they would click on them than an .exe file which is traditionally used by the hacking community."

The flaw affects all versions of DirectX on all Microsoft operating systems, although users of Windows Server 2003 will have less of a problem as the default security settings makes it harder for the malware to run.

If infected, hackers will have access to the PC but will only have user privileges, not full administrator control. A patch is available here.

Microsoft has also released a patch for NT 4, despite the fact that the company no longer provides free support for the operating system.

A problem with the NT 4 Server file management software leaves systems open to denial of service (DoS) attacks.

A cumulative patch has also been issued for SQL Server version 7 and above.

This addresses three problems that could allow malware to launch DoS attacks, cause a buffer overrun or highjack communications between client and server.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java or C++, Senior Developer, London

Java or C++, Senior Developer, London My client is...

ASP .net MVC Developer, C#, Betting, London

ASP .net MVC Developer, C#, Betting, London My client...

Software developer, Web developer, London

Software developer, Web developer, London My client...

Java developer, Online gaming, Agile, London

Java developer, Online gaming, Agile, London My client...

To send to more than one email address, simply separate each address with a comma.