News

Critical Flaw in DirectX Makes Windows Computers Vulnerable

A major security hole in Microsoft's DirectX technology makes it possible for attackers to take over computers running most versions of Windows.

Microsoft warned users of the vulnerability and provided a patch for the problem on Wednesday. The security bulletin can be found at http://www.microsoft.com/technet/security/bulletin/MS03-030.asp.

The flaw is critical on most versions of Windows, including Windows 98, Me, 2000, NT 4 and XP. Like several other vulnerabilities discovered this year, the attack made possible by the flaw is blocked by the default configuration of the Internet Explorer browser in Windows Server 2003. On that operating system, Microsoft labels MS03-030 an "important" security problem.

The problem arises because of two buffer overruns that exist within DirectX when it checks MIDI sound files. The vulnerability is one of those that requires an attacker to send a specially crafted HTML e-mail or lure a user to a specially crafted Web page. Once exploited the flaw can result in the attacker taking control of the machine at the privilege level of the user.

Security researchers at eEye Digital Security reported the problem to Microsoft.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Azure Active Directory ID Protection 'Refresh' Now Available

    Microsoft's enhancements to the Azure Active Directory Identity Protection service are now said to be "generally available" (GA), or ready for commercial use, per a Wednesday announcement.

  • Microsoft Releases Windows 10 Version 1909

    Microsoft on Tuesday announced the release of Windows 10 version 1909, a new operating system product that's also known as the "Windows 10 November 2019 Update."

  • November Microsoft Security Bundle Addresses 75 Vulnerabilities

    Of that number, 13 vulnerabilities are rated "Critical" to patch, while 62 vulnerabilities are deemed "Important."

  • The Future of Office 365 Pricing

    With a raft of new Office 365 features in the pipeline, Microsoft also seems ready to change the way it bills its subscribers. Will it replicate Azure's pay-per-use model, or will it look like something else entirely?

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.