Click Carefully: New DirectX Exploit in the Wild
Another remote hacker threat has arisen, and this time it affects popular streaming media tool DirectX. Microsoft announced yesterday that it is currently working on a fix for the security exploit, which could allow someone to take total control of a system by using malicious QuickTime video files.
DirectX Exploit: Affected Users
The exploit involves Microsoft's audio/video sourcing/rendering software DirectShow and the way it handles the QuickTime format files it supports.
Users of Windows 2000 Service Pack 4, Windows Server 2003, and Windows XP are those most affected and will want to keep on the lookout for Microsoft's patch when it becomes available.
Those running Windows Vista or Microsoft's Windows Server 2008 are lucky; the company has announced that these two systems are not vulnerable to attack. (Source: crn.com)
How Does The Attack Work?
Like many Internet schemes, the attack hinges on convincing a user to visit a malicious web site hosting the exploit. If the exploit is used successfully, a hacker could gain user rights at the same level as a system's rightful owner.
In a statement by its security advisory, Microsoft admitted that it was "aware of limited, active attacks that use this exploit code."
"If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data, or create new accounts with full user rights." (Source: cnet.com)
Workaround Available
Although Microsoft is still working on a more complete solution to the issue, it has released details for a workaround, which you can see by visiting the MS Knowledge base site:
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.