News

Critical Flaw in DirectX Makes Windows Computers Vulnerable

A major security hole in Microsoft's DirectX technology makes it possible for attackers to take over computers running most versions of Windows.

Microsoft warned users of the vulnerability and provided a patch for the problem on Wednesday. The security bulletin can be found at http://www.microsoft.com/technet/security/bulletin/MS03-030.asp.

The flaw is critical on most versions of Windows, including Windows 98, Me, 2000, NT 4 and XP. Like several other vulnerabilities discovered this year, the attack made possible by the flaw is blocked by the default configuration of the Internet Explorer browser in Windows Server 2003. On that operating system, Microsoft labels MS03-030 an "important" security problem.

The problem arises because of two buffer overruns that exist within DirectX when it checks MIDI sound files. The vulnerability is one of those that requires an attacker to send a specially crafted HTML e-mail or lure a user to a specially crafted Web page. Once exploited the flaw can result in the attacker taking control of the machine at the privilege level of the user.

Security researchers at eEye Digital Security reported the problem to Microsoft.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Nebula

    Ahead of AGI, Microsoft and OpenAI Redefine Their Partnership

    In a recapitalization announced Tuesday, OpenAI has launched a new public benefit corporation (PBC) called OpenAI Group, giving Microsoft a 27 percent ownership stake valued at approximately $135 billion.

  • Veeam Acquires Securiti AI To Unify Data Resilience and AI Security

    Veeam Software is making a strategic move into AI and data security by acquiring Securiti AI for $1.7 billion.

  • Microsoft Adds 'Mico' Virtual Assistant to Copilot in Major Fall Update

    In a significant feature update, Microsoft on Thursday said it is reshaping its Copilot AI platform with features that deepen user personalization and enable real-time group collaboration, among other perks.

  • Nutanix Partner Central Rolls Out To Boost Channel Engagement

    Nutanix on Wednesday launched a new platform, Partner Central, to give its channel partners a unified digital workspace for managing sales, tracking incentives and collaborating more effectively.