No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Related Articles

Microsoft, warns, zeroday, DirectShow, vulnerability
The internal security agency MI5 has warned UK businesspeople that agents of the Chinese...
In what is one of the most potentially serious zero-day Microsoft Windows bugs this...
The Month of Apple Bugs may be over, but Kevin Finisterre hasn't given up...
Microsoft has joined forces with Celestix Networks and Network Engines to deliver appliances running...
Early WiMAX networks will have a number of security vulnerabilities, according to ABI Research,...

Microsoft warns of zero-day DirectShow vulnerability

Business IT - Security

There's no fix yet, but Microsoft is warning its customers of a vulnerability in DirectShow in older versions of Windows. The flaw is being exploited.

DirectShow, part of DirectX, is a multimedia framework in Windows used for handling media files. It is used, for example, by Windows Media Player.

The vulnerability affects Windows 2000, XP and Server 2003, but not Vista, Server 2008 or Windows 7.

The problem is that a maliciously formed QuickTime video file passed to DirectShow can lead to remote code execution with the same rights as the current user. Given that so many people use administrator accounts, a successful exploit could take full control of their systems.

As the vulnerability is in DirectShow, it can be exploited whether or not QuickTime is installed on the target system.

A malicious video file could be distributed via email or web sites. In the latter case, viewing the relevant page with any browser that uses DirectShow to handle media files will allow the exploit to do its dirty work.

There's no timeframe for a fix, but Microsoft does offer three workarounds.

Please read on for a link to the most effective and easiest to apply.