News

Critical Flaw in DirectX Makes Windows Computers Vulnerable

A major security hole in Microsoft's DirectX technology makes it possible for attackers to take over computers running most versions of Windows.

Microsoft warned users of the vulnerability and provided a patch for the problem on Wednesday. The security bulletin can be found at http://www.microsoft.com/technet/security/bulletin/MS03-030.asp.

The flaw is critical on most versions of Windows, including Windows 98, Me, 2000, NT 4 and XP. Like several other vulnerabilities discovered this year, the attack made possible by the flaw is blocked by the default configuration of the Internet Explorer browser in Windows Server 2003. On that operating system, Microsoft labels MS03-030 an "important" security problem.

The problem arises because of two buffer overruns that exist within DirectX when it checks MIDI sound files. The vulnerability is one of those that requires an attacker to send a specially crafted HTML e-mail or lure a user to a specially crafted Web page. Once exploited the flaw can result in the attacker taking control of the machine at the privilege level of the user.

Security researchers at eEye Digital Security reported the problem to Microsoft.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.

  • An image of planes flying around a globe

    2025 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Notebook

    Microsoft Centers AI, Security and Partner Dogfooding at MCAPS

    Microsoft's second annual MCAPS for Partners event took place Tuesday, delivering a volley of updates and directives for its partners for fiscal 2026.

  • Microsoft Layoffs: AI Is the Obvious Elephant in the Room

    As Microsoft doubles down on an $80 billion bet on AI this fiscal year, its workforce reductions are drawing scrutiny over whether AI's ascent is quietly reshaping its human capital strategy, even as official messaging avoids drawing a direct line.