News

DirectShow Subject to Attacks, Microsoft Warns

Microsoft issued a security advisory on Friday describing a newly disclosed bug in Microsoft DirectShow that could enable remote code execution attacks.

In its advisory, the software giant said the vulnerability could be triggered if an unsuspecting user opens specially crafted media file. A hacker successfully deploying this bug could increase his user rights privileges within a Windows-based network. However, accounts configured with fewer administrative privileges aren't as vulnerable, Redmond said.

"While our investigation is ongoing, our investigation so far has shown that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are vulnerable," the advisory explained. Currently, Microsoft is aware of "limited, active attacks that exploit this vulnerability."

Users of Windows Vista, Windows 7 RC1 and Windows Server 2008 are not affected by this vulnerability, Redmond said.

Microsoft has rolled out an improved "Software Security Incident Response Process (SSIRP)" to better respond to the issue, the security bulletin explained.

Microsoft DirectShow is a framework that provides an application programming interface for developers working with multimedia files. The framework supplants Microsoft's earlier Video for Windows interface.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • Xamarin.Forms 5 Preview Ships Ahead of .NET 6 Transition to MAUI

    Microsoft shipped a pre-release version of Xamarin.Forms 5 ahead of a planned transition to MAUI, which will take over beginning with the release of .NET 6 in November 2021.

  • ML.NET Improves Object Detection

    Microsoft improved the object detection capabilities of its ML.NET machine learning framework for .NET developers, adding the ability to train custom models with Model Builder in Visual Studio.

  • More Improvements for VS Code's New Python Language Server

    Microsoft announced more improvements for the new Python language server for Visual Studio Code, Pylance, specializing in rich type information.

  • Death of the Dev Machine?

    Here's a takeaway from this week's Ignite 2020 event: An advanced Azure cloud portends the death of the traditional, high-powered dev machine packed with computing, memory and storage components.

  • COVID-19 Is Ignite 2020's Elephant in the Room: 'Frankly, It Sucks'

    As in all things of our new reality, there was no escaping the drastic changes in routine caused by the COVID-19 pandemic during Microsoft's big Ignite 2020 developer/IT pro conference, this week shifted to an online-only event after drawing tens of thousands of in-person attendees in years past.

Upcoming Events