Friday May 29, 2009

Microsoft DirectShow Vulnerability Found, Workarounds Given

The Microsoft Security Response Center (SRC) released a new security advisory that affects DirectShow on Windows 2000, XP, and Server 2003. They’re working on a patch and offer several workarounds to mitigate the risk in the meantime.

Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista. This means that Windows Vista and versions of Windows since Windows Vista (Windows Server 2008, Windows 7) are not vulnerable.

Comments