| Alias/es | MS.DirectShow.NULL.Byte.Overwrite |
| Last Updated Date | Jun 11, 2009 |
| Release Date | Jun 08, 2009 |
| Severity | Critical |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attempt to exploit a NULL-byte-overwrite vulnerability in Microsoft DirectShow.
The vulnerability is caused by an error that occurs when the affected software handles specially crafted QuickTime files. Successful exploitation may lead to remote code execution. |
| Affected Products | DirectX 7.0 on Microsoft Windows 2000 Service Pack 4 DirectX 8.1 on Microsoft Windows 2000 Service Pack 4 DirectX 9.0* on Microsoft Windows 2000 Service Pack 4 DirectX 9.0* on Windows XP Service Pack 2 and Windows XP Service Pack 3 DirectX 9.0* on Windows XP Professional x64 Edition Service Pack 2 DirectX 9.0* on Windows Server 2003 Service Pack 2 DirectX 9.0* on Windows Server 2003 x64 Edition Service Pack 2 DirectX 9.0* on Windows Server 2003 with SP2 for Itanium-based Systems |
| Recommended Actions | See the Microsoft Security Advisory for this issue: http://www.microsoft.com/technet/security/advisory/971778.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1537
|
| Microsoft Bulletin ID | MS09-028 http://www.microsoft.com/technet/security/Bulletin/MS09-028.mspx |
| Reference/s | http://www.securityfocus.com/bid/35139 (BugTraq)
|