MS.DirectShow.AVI.Invalid.JPEGP.Marker

NameMS.DirectShow.AVI.Invalid.JPEGP.Marker.Memory.Corruption
Last Updated DateJun 23, 2009
Release DateApr 14, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a memory-corruption vulnerability
in Microsoft DirectShow.

The vulnerability is caused by an error when the affected software handles specially crafted MJPEG files. Successful exploitation may lead to remote code execution.
Affected ProductsMicrosoft Windows 2000 Service Pack with DirectX 8.1
Microsoft Windows 2000 Service Pack 4 with DirectX 9.0
Windows XP Service Pack 2 and Windows XP Service Pack 3 with DirectX 9.0
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 with DirectX 9.0
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 with DirectX 9.0
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 with DirectX 9.0
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems with DirectX 9.0
Recommended ActionsApply the patch, available from the vendor's website:
http://www.microsoft.com/technet/security/Bulletin/ms09-011.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0084
Microsoft Bulletin IDMS09-011   http://www.microsoft.com/technet/security/Bulletin/ms09-011.mspx
Reference: VID-17389