Executive brief
A vulnerability in Microsoft DirectX's media processing component could allow an attacker to take control of a computer if a user opens a specially crafted QuickTime movie file. This issue affects older versions of Windows, including Windows XP and Server 2003, and has been observed being used in active attacks. An exploit could lead to a total loss of data confidentiality and system availability, potentially allowing unauthorized software installation or data theft.
Technical details
A NULL byte overwrite vulnerability exists in the QuickTime Movie Parser Filter (quartz.dll) within Microsoft DirectShow, a component of DirectX. The flaw is triggered when the parser processes a maliciously crafted QuickTime (.mov) media file. An attacker can exploit this by hosting the file on a website or sending it via email, requiring the user to open the file or visit a malicious page. Successful exploitation allows for remote code execution with the privileges of the logged-in user. This vulnerability was notably exploited in the wild in 2009 and is addressed in Microsoft Security Bulletin MS09-028.
Affected products
- Microsoft DirectX 7.0 through 9.0c
- Microsoft Windows 2000 SP4
- Microsoft Windows XP SP2 and SP3
- Microsoft Windows Server 2003 SP2
Timeline
- 2009-05-28: advisory: Initial Microsoft Security Advisory 971778 released
- 2009-05-29: disclosed: NVD Published Date
- 2009-05-01: exploited: Exploited in the wild in May 2009
- 2009-07-14: patched: Formal patch released via MS09-028