Microsoft warns Windows 2000/XP DirectX new vulnerability

  

Microsoft recently released security bulletin No. 971778, warning that there is a new security vulnerability in the QuickTime splitter of the DirectX DirectShow component.
This vulnerability exists in DirectX 7.0/8.1/9.0 and other versions, involving Windows 2000/XP/Server 2003, and because Microsoft has removed the vulnerability code when developing Windows Vista/Server 2008 and DirectX 10.0/10.1. Therefore, it is not affected, including future Windows 7 and DirectX 11.

Microsoft said the vulnerability has been made public and has triggered a limited security attack. If a user opens a specially crafted QuickTime media file in a browser, the vulnerability is induced, causing remote code execution and allowing the attacker to gain local user rights.

Microsoft did not disclose when to release the relevant patch. By convention, it should be the second Tuesday of June, which is the local time on the 9th.

Copyright © Windows knowledge All Rights Reserved