KB941568: KB 941568: MS07064: MS07-064

Posted By: ensiform

Two vulnerabilities have been identified in Microsoft’s DirectX which have the potential for remote code execution.

These vulnerabilities are generally exploited by watching a streaming video file via DirectX while logged in with administrator rights. An attacker could take total control over the compromised system and install programs, view private data, delete data, or even create new accounts with full control which they can access. Microsoft has ranked this as Critical which is the highest rank of security update, and strongly encourages all affected users to update immediately if not already done so via Automatic Updates.

For a more detailed description and further information involving this, please visit these links:

Home Users

IT Professionals

The update applies to the following products:

  • Microsoft DirectX 7.0 Runtime
  • Microsoft DirectX 8.x Runtime
  • Microsoft DirectX 9.0 Runtime
  • Microsoft DirectX 10 Runtime

Operating systems affected by these vulnerabilities with DirectX:

  • Windows 2000 Service Pack 4
  • Windows 2000 Professional Edition
  • Windows 2000 Datacenter Server
  • Windows 2000 Advanced Server
  • Windows Server 2003 Service Pack 1, when used with:
    • Windows Server 2003, Web Edition
    • Windows Server 2003, Datacenter Edition (32-bit x86)
    • Windows Server 2003, Enterprise Edition (32-bit x86)
    • Windows Server 2003, Standard Edition (32-bit x86)
    • Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Windows Server 2003 Service Pack 2, when used with:
    • Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Windows Server 2003, Enterprise Edition for Itanium-based Systems
    • Windows Server 2003, Web Edition
    • Windows Server 2003, Datacenter Edition (32-bit x86)
    • Windows Server 2003, Enterprise Edition (32-bit x86)
    • Windows Server 2003, Standard Edition (32-bit x86)
    • Windows Server 2003, Standard x64 Edition
    • Windows Server 2003, Datacenter x64 Edition
    • Windows Server 2003, Enterprise x64 Edition
  • Windows XP Professional x64 Edition
  • Windows XP Service Pack 2, when used with:
    • Windows XP Professional
    • Windows XP Home Edition
    • Windows XP Professional x64 Edition
  • Windows Vista Business
  • Windows Vista Enterprise
  • Windows Vista Home Basic
  • Windows Vista Home Premium
  • Windows Vista Ultimate
  • Windows Vista Business 64-bit Edition
  • Windows Vista Enterprise 64-bit Edition
  • Windows Vista Home Basic 64-bit Edition
  • Windows Vista Home Premium 64-bit Edition
  • Windows Vista Ultimate 64-bit Edition

Keywords: kbexpertiseinter kbexpertisebeginner kbqfe kbsecurity kbsecbulletin kbsecvulnerability kbbug kbfix kbpubtypekc KB941568 KB 941568 MS07064 MS07-064

Original Microsoft Support Article:
http://support.microsoft.com/kb/941568/en-us

Comment:

Valid XHTML 1.0 Transitional

Valid CSS!

eXTReMe Tracker